Re: cvs: php4 /ext/standard string.c

From: Date: Sun, 26 Aug 2001 09:41:16 +0000
Subject: Re: cvs: php4 /ext/standard string.c
References: 1  Groups: php.cvs 
Request: Send a blank email to php-cvs+get-7070@lists.php.net to get a copy of this message
hi, the buffer overrun is the minor problem - i have seen many scripts that strip php tags before saving user input as .php. this was relatively safe, but after this change there is no guarantee that the result does not contain php code... for example <?xmlfoo(); function xmlfoo(){} do_something_nasty()?> will be interpreted as an xml tag, not a php one by strip_tags while php itself will parse it like code. i think this is inconsistent with the way the php parser works and is a possible scurity problem. when a user strips php tags with a native php's function she expects to really strip them. not to speak that this code does not check for <% .... %>... anyway. lets think about a solution - maybe change the engine's way of parsing <?xml or add an option to strip_tags? the latter is the easiest and maybe with a proper note in the docs will do... b. > Are you sure that when you do p+2 and p+3 that you are definitely not > passing the end of the string? I don't have time to go over the code now > but it looks dangerous. > > Andi

« previous php.cvs (#7070) next »