security, receiving html from a form
| From: | Matt Greer | Date: | Thu, 19 Jul 2001 01:32:45 +0000 |
| Subject: | security, receiving html from a form | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-58593@lists.php.net to get a copy of this message | ||
For my website I created an updating system in php. Where my staff and I can
write articles that then get saved to the server, linked to, etc. I allowed
html to be passed from the form because a lot of the staff likes to use html
tags in their articles. Which I know is a security issue.
I know I could use HTMLSpecialChars() and then devise my own mark up system;
which I will if I have no other alternative. But I was wondering if just
searching the article string for "<?", "?>", "<script", etc
and not writing
the file if they're found would suffice. That almost seems too simple
though.
Thanks,
Matt