Re: ereg_replace question
| From: | Daniel Convissor | Date: | Thu, 12 Oct 2000 21:13:23 +0000 |
| Subject: | Re: ereg_replace question | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-19892@lists.php.net to get a copy of this message | ||
Sire:
> <cmt The Master>This is a comment</cmt>
> and return
> <i>The Master comments: This is a comment</i>
>
> I thought this would do it:
> ereg_replace("(<cmt (.*)>(.*)</cmt>)","<i>\\2 comments:
> \\3</i>",$string)
>
> but it doesn't.
> I'm running PHP 4.0b3 on Red Hat 6.1.
Works fine for me. PHP 4.0.3, NT 4, Apache.
> It also COMPLETELY fails on text that contains
> <b>...</b> within the \\3 section, ie:
>
> <cmt The Master>This is <b>a</b> comment</cmt>
Now, this, in reality, should not be an issue. I'm guessing you're setting
up something for people to submit input. You'd be ill advised to let them
stick in HTML. Doing so presents security risks, permitting users to inject
scripts which can do some nasty things. See
http://www.cert.org/advisories/CA-2000-02.html
for more information. HTML
should be stripped out upon submission.
Enjoy,
--Dan
--
T H E A N A L Y S I S A N D S O L U T I O N S C O M P A N Y
More than just answers. Solutions. (SM)
http://www.analysisandsolutions.com/
4015 7 Av #4, Brooklyn NY 11232 v: 718-854-0335 f: 718-854-0409