Bug #66111 [Opn->Nab]: strip_tags strip <=

From: Date: Wed, 20 Nov 2013 14:54:51 +0000
Subject: Bug #66111 [Opn->Nab]: strip_tags strip <=
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-182864@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66111&edit=1 ID: 66111 Updated by: johannes@php.net Reported by: 22rist at gmail dot com Summary: strip_tags strip <= -Status: Open +Status: Not a bug Type: Bug Package: Filter related Operating System: windows 7 x64 PHP Version: 5.5Git-2013-11-18 (Git) Block user comment: N Private report: N New Comment: Browsers are quite error tolerant in parsing HTML. strip_tags tries to be secure with the risk of breaking input. If you want to take data into HTML and want the browser to render it properly use htmlentities etc. Previous Comments: ------------------------------------------------------------------------ [2013-11-20 14:46:43] anon at anon dot anon The subject is that you're misusing the function. strip_tags removes tags from HTML. This is not valid HTML: Mileage <= 15000 Now read the warning in the documentation: Because strip_tags() does not actually validate the HTML, partial or broken tags can result in the removal of more text/data than expected. I.e., garbage in = garbage out. ------------------------------------------------------------------------ [2013-11-20 14:18:34] 22rist at gmail dot com The subject is "The function strip_tags should strip tags and only tags". Not "How I use strip_tags". Or "how somebody filter comments". So if you can't write something related to the subject please do not spam. ------------------------------------------------------------------------ [2013-11-20 13:59:45] anon at anon dot anon Why would someone write that? Oh wait, you just did. Can you imagine how annoying it would be for you to type your comment if this bug page used strip_tags? ------------------------------------------------------------------------ [2013-11-20 13:35:03] 22rist at gmail dot com Ok, htmlspecilachars will prevent XSS. But I want to STRIP TAGS. I want to see "Please use google.com" when user write "<b>Please</b> use <a href="https://www.google.com">google.com</a>" AND NOT an encoded variant of "<b>Please</b> use <a href="https://www.google.com">google.com</a>" as htmlspecilachars do. ------------------------------------------------------------------------ [2013-11-20 13:17:15] anon at anon dot anon There's a very easy way to prevent XSS and allow "Mileage <= 15000". It's called htmlspecialchars. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=66111 -- Edit this bug report at https://bugs.php.net/bug.php?id=66111&edit=1

« previous php.bugs (#182864) next »