Bug #80095 [NEW]: dom document parsing inline javascript errors
| From: | shariefjamiel at gmail dot com | Date: | Sat, 12 Sep 2020 11:06:06 +0000 |
| Subject: | Bug #80095 [NEW]: dom document parsing inline javascript errors | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-228983@lists.php.net to get a copy of this message | ||
From: shariefjamiel at gmail dot com
Operating system: ubuntu 20.04
PHP version: 7.4Git-2020-09-12 (Git)
Package: DOM XML related
Bug Type: Bug
Bug description:dom document parsing inline javascript errors
Description:
------------
When loading HTML in the DOMDocument with an inline script within a DIV
and there is javascript with DIV html, the ending script tag gets put in
the wrong place.
Notice the closing script tag, its been put in the wrong place
.append("<div class=\"d-flex\"><div class=\"column\">" +
item.value +
"</script></div>
In this case removing the outer div, fixes the problem or escaping the
html within the javascript append method.
Test script:
---------------
<?php
$html = <<< EOT
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1,
shrink-to-fit=no">
</head>
<body>
<div class="if-you-remove-me-everything-is-fine">
<script>
function initialize() {
$('#search').autocomplete({
source: '/api/search',
minLength: 2,
autoFocus: true,
}).autocomplete("instance")._renderItem = function(ul, item)
{
return $("<li>")
.append("<div class=\"d-flex\"><div
class=\"column\">" + item.value + "</div> <div
class=\"flex-grow-1\">" +
item.label + "</div> <div class=\"column text-right\">" +
item.exchange
+ "</div> </div>")
.appendTo(ul);
};
}
</script>
</div>
</body>
</html>
EOT;
/**
* Two ways to solve problem
*
* 1. remove outer div
* 2. escape the html contents in javascript
*/
$doc = new DOMDocument();
$doc->loadHTML($html, LIBXML_HTML_NODEFDTD);
echo $doc->saveHTML();
Expected result:
----------------
Expect the ending script tag to be put where it was
Actual result:
--------------
The script tag was placed inside the inline javascript code
--
Edit bug report at https://bugs.php.net/bug.php?id=80095&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=80095&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=80095&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=80095&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=80095&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=80095&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=80095&r=support
Expected behavior: https://bugs.php.net/fix.php?id=80095&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=80095&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=80095&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=80095&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=80095&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=80095&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=80095&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=80095&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=80095&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=80095&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=80095&r=mysqlcfg