Bug #15972 Updated: strip_tags should allow restricting the attributes on tags that are kept

From: Date: Thu, 02 May 2002 20:10:59 +0000
Subject: Bug #15972 Updated: strip_tags should allow restricting the attributes on tags that are kept
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-6779@lists.php.net to get a copy of this message
 ID:               15972
 Updated by:       jimw@php.net
-Summary:          strip_tags allows javascript
 Reported By:      rn214@cam.ac.uk
 Status:           Open
 Bug Type:         Feature/Change Request
 Operating System: Linux
 PHP Version:      4.0.6
 New Comment:

rewrote the summary. it would be nice if the syntax were something
like: strip_tags($text, "a[href,target],br,p")


Previous Comments:
------------------------------------------------------------------------

[2002-03-09 12:08:43] rn214@cam.ac.uk

Oops - that should be 

...javascript:document...

------------------------------------------------------------------------

[2002-03-09 11:56:50] rn214@cam.ac.uk

The html strip_tags() function permits any attributes. This gives a
security hole. Eg allowing <b> also permits:

<b onclick="javascript.document.location='http://www.evil.com';">

That's not so nice !

Context: I run a website in which I want to allow (untrusted) users to
post messages formatted with a very limited subset of html. I don't
want them to be able to do anything nasty.

I am aware that this may not really be a bug per se, and might be
better as a new string function ('vanilla_tags'). But it could bite the
unwary.

Thanks a lot

Richard

------------------------------------------------------------------------


-- 
Edit this bug report at http://bugs.php.net/?id=15972&edit=1



Thread (5 messages)

« previous php.bugs (#6779) next »