Bug #64430 [Opn->Nab]: strip_tags() clobbers non-tag entities

From: Date: Wed, 07 Oct 2020 15:21:37 +0000
Subject: Bug #64430 [Opn->Nab]: strip_tags() clobbers non-tag entities
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229452@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64430&edit=1 ID: 64430 Updated by: cmb@php.net Reported by: gdataonline at gmail dot com Summary: strip_tags() clobbers non-tag entities -Status: Open +Status: Not a bug Type: Bug Package: Strings related Operating System: Windows 7 x64 PHP Version: 5.4.13 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: strip_tags() does not validate the HTML, and works along the lines of "better safe than sorry", so this is expected behavior, which is also documented[1]: | Because strip_tags() does not actually validate the HTML, | partial or broken tags can result in the removal of more text/data | than expected. [1] <https://www.php.net/manual/en/function.strip-tags.php> Previous Comments: ------------------------------------------------------------------------ [2015-03-31 10:42:59] marcosgdf at gmail dot com I'm having the same problem. Test script: --------------- <?php var_dump(strip_tags('This is not HTML, <email@email.com> is not a valid tag')); Expected result: ---------------- string(54) "This is not HTML, <email@email.com> is not a valid tag" Actual result: -------------- string(37) "This is not HTML, is not a valid tag" ------------------------------------------------------------------------ [2013-03-15 19:55:52] gdataonline at gmail dot com I'm starting to suspect that strip_tags treats anything that matches <[^>\s]*> as an HTML tag, regardless of where it appears or if it's valid HTML. ------------------------------------------------------------------------ [2013-03-15 15:15:58] gdataonline at gmail dot com Description: ------------ strip_tags() will clobber all remaining input after encountering non-HTML tags, regardless if embedded in "allowable-tags". When strip_tags() encounters a "<" followed by *any non-whitespace*, it assumes it's an HTML tag, even if it couldn't legally be one. In the example below, even something as simple as a "<=" appearing in JavaScript is enough to trigger the behavior. For a full list of characters that strip_tags() clobbers on, see this example: http://ideone.com/BEPINI Test script: --------------- <?php // Example 1: Without <= $code = "<script>if (foo >= bar){ alert(0); }</script>"; var_dump(strip_tags($code)); var_dump(strip_tags($code, "<script>")); // Example 2: With <= $code = "<script>if (foo <= bar){ alert(0); }</script>"; var_dump(strip_tags($code)); var_dump(strip_tags($code, "<script>")); ?> Expected result: ---------------- string(28) "if (foo >= bar){ alert(0); }" string(45) "<script>if (foo >= bar){ alert(0); }</script>" string(28) "if (foo <= bar){ alert(0); }" string(45) "<script>if (foo <= bar){ alert(0); }</script>" Actual result: -------------- string(28) "if (foo >= bar){ alert(0); }" string(45) "<script>if (foo >= bar){ alert(0); }</script>" string(8) "if (foo " string(16) "<script>if (foo " ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=64430&edit=1

« previous php.bugs (#229452) next »