Re: cvs: php4 /ext/standard string.c
| From: | Boian Bonev | Date: | Sun, 26 Aug 2001 09:41:16 +0000 |
| Subject: | Re: cvs: php4 /ext/standard string.c | ||
| References: | 1 | Groups: | php.cvs |
| Request: | Send a blank email to php-cvs+get-7070@lists.php.net to get a copy of this message | ||
hi,
the buffer overrun is the minor problem - i have seen many scripts that
strip php tags before saving user input as .php. this was relatively safe,
but after this change there is no guarantee that the result does not contain
php code...
for example
<?xmlfoo(); function xmlfoo(){} do_something_nasty()?>
will be interpreted as an xml tag, not a php one by strip_tags while php
itself will parse it like code. i think this is inconsistent with the way
the php parser works and is a possible scurity problem.
when a user strips php tags with a native php's function she expects to
really strip them. not to speak that this code does not check for <% ....
%>...
anyway. lets think about a solution - maybe change the engine's way of
parsing <?xml or add an option to strip_tags? the latter is the easiest and
maybe with a proper note in the docs will do...
b.
> Are you sure that when you do p+2 and p+3 that you are definitely not
> passing the end of the string? I don't have time to go over the code now
> but it looks dangerous.
>
> Andi