Re: [RFC] Improve HTML escape

From: Date: Mon, 03 Feb 2014 22:21:45 +0000
Subject: Re: [RFC] Improve HTML escape
References: 1 2 3 4 5 6 7 8  Groups: php.internals 
Request: Send a blank email to internals+get-72147@lists.php.net to get a copy of this message
Hi Stas, On Tue, Feb 4, 2014 at 7:14 AM, Stas Malyshev <smalyshev@sugarcrm.com>wrote: > > Some users has to confirm standard like PCI DSS. > > PCI DSS requires to follow security standards and guidelines from OWASP, > > SANS, etc. > > > > Why not make PHP standard compliant? > > It does not hart existing applications at all and this is simple enough > > change. > > I'm sorry, could you please quote me a standard that requires PHP to > escape / in function called htmlentites? I've already written the URL to OWASP. PCI DSS v3 states in section 6.5 Develop applications based on secure coding guidelines. Note: The vulnerabilities listed at 6.5.1 through 6.5.10 were current with industry best practices when this version of PCI DSS was published. However, as industry best practices for vulnerability management are updated (for example, the OWASP Guide, SANS CWE Top 25, CERT Secure Coding, etc.), the current best practices must be used for these requirements. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#72147) next »