security, receiving html from a form

From: Date: Thu, 19 Jul 2001 01:32:45 +0000
Subject: security, receiving html from a form
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-58593@lists.php.net to get a copy of this message
For my website I created an updating system in php. Where my staff and I can write articles that then get saved to the server, linked to, etc. I allowed html to be passed from the form because a lot of the staff likes to use html tags in their articles. Which I know is a security issue. I know I could use HTMLSpecialChars() and then devise my own mark up system; which I will if I have no other alternative. But I was wondering if just searching the article string for "<?", "?>", "<script", etc and not writing the file if they're found would suffice. That almost seems too simple though. Thanks, Matt

« previous php.general (#58593) next »