Bug #74371 [PATCH]: strip_tags altering attributes

From: Date: Thu, 03 Dec 2020 22:46:31 +0000
Subject: Bug #74371 [PATCH]: strip_tags altering attributes
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230828@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74371&edit=1

 ID:                 74371
 Patch added by:     cmb@php.net
 Reported by:        php-bugs at aspectis dot net
 Summary:            strip_tags altering attributes
 Status:             Verified
 Type:               Bug
 Package:            *General Issues
 PHP Version:        7.1.3
 Block user comment: N
 Private report:     N

 New Comment:

The following pull request has been associated:

Patch Name: Fixed bug #74371 strip_tags altering attributes
On GitHub:  https://github.com/php/php-src/pull/3570
Patch:      https://github.com/php/php-src/pull/3570.patch


Previous Comments:
------------------------------------------------------------------------
[2020-09-07 12:28:27] ad at asd dot com

"><img src=1 href=1 onerror="javascript:alert(1)"></img>

------------------------------------------------------------------------
[2017-08-12 01:04:34] ajf@php.net

Looks like a real bug to me.

One solution might be to round-trip it through an HTML parser (say, DOMDocument) first.

------------------------------------------------------------------------
[2017-04-04 20:28:44] spam2 at rhsoft dot net

you don't get it - the whole purpose of strip_tags is to get rid auf dangerous chars like <
and >

------------------------------------------------------------------------
[2017-04-04 19:56:53] php-bugs at aspectis dot net

This may be true for XHTML, but in HTML 4 and 5 "<" and ">" are perfectly
valid characters for attribute values.

------------------------------------------------------------------------
[2017-04-04 19:45:39] spam2 at rhsoft dot net

your source code is just plain wrong when it contains < or > because these chars needs to be
encoded as entities and the whole purpose of strip_tags() is to FIX such issues to PREVENT that your
tag itself get closed by unencoded value

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=74371


--
Edit this bug report at https://bugs.php.net/bug.php?id=74371&edit=1


Thread (7 messages)

« previous php.bugs (#230828) next »