Sec Bug->Bug #70720 [Opn]: strip_tags improper php code parsing
| From: | jpauli@php.net | Date: | Tue, 22 Dec 2015 14:15:26 +0000 |
| Subject: | Sec Bug->Bug #70720 [Opn]: strip_tags improper php code parsing | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-198138@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70720&edit=1
ID: 70720
Updated by: jpauli@php.net
Reported by: admin at sinfocol dot org
Summary: strip_tags improper php code parsing
Status: Open
-Type: Security
+Type: Bug
Package: Strings related
Operating System: Any
PHP Version: Irrelevant
-Assigned To:
+Assigned To: jpauli
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2015-10-15 14:54:59] admin at sinfocol dot org
Description:
------------
Hello,
The strip_tags function stop the processing of php code until the next ">" is found if
the string "xml" is included within php tags.
Test script:
---------------
<?php
var_dump(strip_tags('<?php $dom->test(); ?> this is a test'));
var_dump(strip_tags('<?php $xml->test(); ?> this is a test'));
Expected result:
----------------
string(15) " this is a test"
string(15) " this is a test"
Actual result:
--------------
string(15) " this is a test"
string(25) "test(); ?> this is a test"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70720&edit=1