Bug #2477: Possible strip_tags() and fgetss() vulnerability
| From: | deicide at gameaholic dot com | Date: | Sun, 10 Oct 1999 04:42:14 +0000 |
| Subject: | Bug #2477: Possible strip_tags() and fgetss() vulnerability | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-11659@lists.php.net to get a copy of this message | ||
From: deicide@gameaholic.com
Operating system:
PHP version: 3.0.12
PHP Bug Type: Other
Bug description: Possible strip_tags() and fgetss() vulnerability
Last week a "mis-feature" was reported on Bugtraq regarding some Netscape versions that
treat 0x8b and 0x9b characters as [less than] and [greater than] signs.
I do not personally have a platform that was confirmed to be vulnerable so I can't actually
test this under PHP, but the issue seems to be quite easy to fix. The thread on Bugtraq can be
viewed at the link below. The fix would be to modify strip_tags() and fgetss() functions to tread
0x8b and 0x9b characters equally to [less than] and [greater than] characters while parsing out HTML
tags.
http://www.securityfocus.org/templates/archive.pike?list=1&date=1999-10-01&thread=Pine.SGI.4.05.9910051008450.149247-100000@tiger.coe.missouri.edu