Re: security, receiving html from a form

From: Date: Thu, 19 Jul 2001 03:45:07 +0000
Subject: Re: security, receiving html from a form
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-58605@lists.php.net to get a copy of this message
----- Original Message ----- From: "Rasmus Lerdorf" <rasmus@php.net> > > I know I could use HTMLSpecialChars() and then devise my own mark up system; > > You could also define a list of tags you allow and pass them to the > strip_tags() function. See http://php.net/strip_tags > Interesting. Thanks for the link, it gave me some good stuff to think about. strip_tags() appears to have some holes in it, but the comments offered provided some work arounds. Matt

« previous php.general (#58605) next »