RE: [PHP] HREF exploit
| From: | David Norman | Date: | Wed, 26 Jul 2000 21:49:30 +0000 |
| Subject: | RE: [PHP] HREF exploit | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-8417@lists.php.net to get a copy of this message | ||
I understand that and I have a filter I'm faily confident will filter out
<p> tags, but I'd like to allow HREF tags and having one quote in it might
not be someone trying to exploit the system as much as it might just be a
typo.
-----Original Message-----
From: Rasmus Lerdorf [mailto:rasmus@php.net]
Sent: Wednesday, July 26, 2000 4:47 PM
To: David Norman
Cc: php-general@lists.php.net
Subject: Re: [PHP] HREF exploit
Not to burst your bubble or anything, but it is pretty much impossible to
allow people to enter HTML on your page in any sort of secure
manner. Even a <p> tag can be used maliciously by embedding JavaScript in
it that ends up redirecting users elsewhere, or worse.
-Rasmus