Re: [RFC] Improve HTML escape
| From: | Stas Malyshev | Date: | Mon, 03 Feb 2014 22:24:22 +0000 |
| Subject: | Re: [RFC] Improve HTML escape | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72148@lists.php.net to get a copy of this message | ||
Hi!
> I've already written the URL to OWASP.
>
> PCI DSS v3 states in section 6.5
>
> Develop applications based on secure coding guidelines.
Secure coding guidelines in this case is to not use htmlentities in this
context. If you already violate this requirement, why would you expect
PHP to un-violate it for you?
--
Stanislav Malyshev, Software Architect
SugarCRM: http://www.sugarcrm.com/
(408)454-6900 ext. 227