Bug #76184 [Com]: string beginning with < error
| From: | spam2 at rhsoft dot net | Date: | Wed, 04 Apr 2018 19:47:52 +0000 |
| Subject: | Bug #76184 [Com]: string beginning with < error | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-214598@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76184&edit=1
ID: 76184
Comment by: spam2 at rhsoft dot net
Reported by: jalesmonteiro at hotmail dot com
Summary: string beginning with < error
Status: Open
Type: Bug
Package: Strings related
Operating System: UBUNTU 17.10
PHP Version: 7.1.16
Block user comment: N
Private report: N
New Comment:
> "rhsoft" continues their aggressive behaviour on the bug
> tracker still too. One recent illustration is
> https://bugs.php.net/bug.php?id=76184&edit=1
what exactly is aggressive here?
"Strings beginning with the '<' char can't be printed" is simply not
true, can be easily proven by run the "sample code" within a shell or just right click in
Firefox and select "show page source"
the fact that such strings needs to be properly handeled with htmlentities() is security relevant as
we have enough code in the wild with not the sligtest thoughs about security
Previous Comments:
------------------------------------------------------------------------
[2018-04-04 16:46:23] spam2 at rhsoft dot net
> the function count_chars also return the expected
the output too, open the damned source of the website in yur browser and you see
------------------------------------------------------------------------
[2018-04-04 16:44:13] jalesmonteiro at hotmail dot com
the function count_chars also return the expected.
------------------------------------------------------------------------
[2018-04-04 16:44:01] spam2 at rhsoft dot net
nonsense - they are printed and you wrote perfect sample code how not to do it open for injection by
not care about special chars - look at the source code of the page and you see them
RTFM of basic HTML and use http://php.net/manual/en/function.htmlentities.php
if you come up with something like "Strings beginning with the '<' char can't
be printed" first run your script in a terminal and then spend 2 seconds what the output means
for a HTML renderer
------------------------------------------------------------------------
[2018-04-04 16:39:50] jalesmonteiro at hotmail dot com
Description:
------------
Strings beginning with the '<' char can't be printed.
The functions strlen and ctype_print show the return the expected, however the echo and print shows
nothing.
Test script:
---------------
<?php
$str = '<Hello>';
echo strlen($str);
echo '<br/>';
echo ctype_print($str);
echo '<br/>';
foreach (count_chars($str, 1) as $i => $val) {
echo 'There were '.$val.' instance(s) of "' , chr($i) , '" in
the string.';
echo '<br/>';
}
echo $str;
?>
Expected result:
----------------
7
1
There were 1 instance(s) of "<" in the string.
There were 1 instance(s) of ">" in the string.
There were 1 instance(s) of "H" in the string.
There were 1 instance(s) of "e" in the string.
There were 2 instance(s) of "l" in the string.
There were 1 instance(s) of "o" in the string.
<Hello>
Actual result:
--------------
7
1
There were 1 instance(s) of "<" in the string.
There were 1 instance(s) of ">" in the string.
There were 1 instance(s) of "H" in the string.
There were 1 instance(s) of "e" in the string.
There were 2 instance(s) of "l" in the string.
There were 1 instance(s) of "o" in the string.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76184&edit=1