Re: [RFC] Improve HTML escape
| From: | Sara Golemon | Date: | Sun, 02 Feb 2014 03:15:00 +0000 |
| Subject: | Re: [RFC] Improve HTML escape | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-71969@lists.php.net to get a copy of this message | ||
On Sat, Feb 1, 2014 at 7:09 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> This is a little improvement for HTML escape.
> https://wiki.php.net/rfc/secure-html-escape
>
> "/" escape is recommended by OWASP and we may follow them.
>
Could you include some samples of malicious input and what the output
would actually look like? It's not obvious from the RFC or the link
referenced.
-Sara