Bug #73767 [Opn->Nab]: script in document.write (string) in <script> in html get corrupted
| From: | yohgaki@php.net | Date: | Sat, 17 Dec 2016 00:59:48 +0000 |
| Subject: | Bug #73767 [Opn->Nab]: script in document.write (string) in <script> in html get corrupted | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-206086@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73767&edit=1
ID: 73767
Updated by: yohgaki@php.net
Reported by: justin dot maxwell at tibit dot com
Summary: script in document.write (string) in <script> in
html get corrupted
-Status: Open
+Status: Not a bug
Type: Bug
Package: DOM XML related
Operating System: Mint 18
PHP Version: 7.0.14
Block user comment: N
Private report: N
New Comment:
Besides chars in the string must be URL encoded or entity at least, and this kind of simple
JavaScript injections must be prevented at program that generates JavaScript.
Why you think JavaScript code
'<scr'+'ipt src="http://example.com/some.js"></scr'+'ipt>'
must yield
'<scr'+'ipt src="http://example.com/some.js">'+'ipt>'
?
This is totally wrong thing to do. Contents inside script tag is CDATA and it must return string as
it is.
BTW, if your system allows such string generation from user's inputs, there is no reliable way
to prevent injection attacks.
Previous Comments:
------------------------------------------------------------------------
[2016-12-16 23:38:33] justin dot maxwell at tibit dot com
Description:
------------
---
From manual page: http://www.php.net/book.libxml
---
PHP 7.0.8-0ubuntu0.16.04.3
I have no control of the site with this erm, <expletive> oldskool hacky code in it, but I need
to parse it.
See the HTML snippet in the test script for details, but after loadHTML, saveHTML, the string
parameter to document.write is missing a piece.
On input, it is: '<scr'+'ipt src="http://example.com/some.js"></scr'+'ipt>'
On output : '<scr'+'ipt src="http://example.com/some.js">'+'ipt>'
Which of course wreaks havoc with the unclosed injected script tag.
Incidentally, : '<scr'+'ipt src="http://example.com/some.js"><'+'/scr'+'ipt>'
... on first glance, seems to be parsed without corruption.
Test script:
---------------
Using HTML as beneath
$doc= new DOMDocument();
$doc->loadHTMLFile('test-libxml.html');
$doc->saveHTML();
<!DOCTYPE html>
<html>
<head>
<title>Test libxml</title>
</head>
<body>
<script type="text/javascript">
document.write('<scr'+'ipt src="http://example.com/some.js"></scr'+'ipt>');
</script>
</body>
</html>
Expected result:
----------------
<!DOCTYPE html>
<html>
<head>
<title>Test libxml</title>
</head>
<body>
<script type="text/javascript">
document.write('<scr'+'ipt src="http://example.com/some.js">'+'ipt>');
</script>
</body>
</html>
Actual result:
--------------
<!DOCTYPE html>
<html>
<head>
<title>Test libxml</title>
</head>
<body>
<script type="text/javascript">
document.write('<scr'+'ipt src="http://example.com/some.js"></scr'+'ipt>');
</script>
</body>
</html>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73767&edit=1