Bug #66111 [Com]: strip_tags strip <=

From: Date: Wed, 20 Nov 2013 13:17:15 +0000
Subject: Bug #66111 [Com]: strip_tags strip <=
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-182857@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66111&edit=1 ID: 66111 Comment by: anon at anon dot anon Reported by: 22rist at gmail dot com Summary: strip_tags strip <= Status: Open Type: Bug Package: Filter related Operating System: windows 7 x64 PHP Version: 5.5Git-2013-11-18 (Git) Block user comment: N Private report: N New Comment: There's a very easy way to prevent XSS and allow "Mileage <= 15000". It's called htmlspecialchars. Previous Comments: ------------------------------------------------------------------------ [2013-11-20 12:23:45] 22rist at gmail dot com In security reasons (to prevent XSS) I should strip all tags in user comments. It's not a developer blog and there wont be conversation about HTML. And your comment "they want to talk about HTML." is not related to the subject. The subject is "The function strip_tags should strip tags and only tags". ------------------------------------------------------------------------ [2013-11-20 12:12:16] anon at anon dot anon >There can be tags that I must strip. In other words, you're trying to make it a nuisance for anyone on the off chance they want to talk about HTML. strip_tags is the wrong function. Use htmlspecialchars. ------------------------------------------------------------------------ [2013-11-19 14:18:59] 22rist at gmail dot com This text can be in comments. Some of this comments can be from user. There can be tags that I must strip. But there can be "Mileage <= 15000" that I shouldn't streep. What should I do? ------------------------------------------------------------------------ [2013-11-19 13:10:30] anon at anon dot anon strip_tags converts HTML to plain text. If you're typing "Mileage <= 15000", that's not HTML, it's text, so strip_tags is the wrong function. Use htmlspecialchars. ------------------------------------------------------------------------ [2013-11-18 08:33:10] 22rist at gmail dot com Description: ------------ Very hard to explain copywriter, that he should not use "<=" in his text for security purposes. Test script: --------------- $text = "Mileage <= 15000"; print_r(strip_tags($text)); //print: Mileage Expected result: ---------------- Mileage <= 15000 Actual result: -------------- Mileage ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66111&edit=1

« previous php.bugs (#182857) next »