Re: New escaped output operator

From: Date: Sun, 19 Jun 2016 18:42:39 +0000
Subject: Re: New escaped output operator
References: 1 2 3 4 5 6 7 8 9 10 11 12  Groups: php.internals 
Request: Send a blank email to internals+get-94134@lists.php.net to get a copy of this message
On 19.06.2016 at 19:28, Scott Arciszewski wrote: > Further reading: > > https://paragonie.com/blog/2015/06/preventing-xss-vulnerabilities-in-php-everything-you-need-know Thanks! Minor issue: | If you failed to specify ENT_QUOTES and attacker simply needs to pass | " onload="malicious javascript code as a value to that form field and | presto, instant client-side code execution. That's not correct, unless ENT_NOQUOTES would have been specified. The default of htmlspecialchars() is to escape double-quotes, but to leave single-quotes alone. -- Christoph M. Becker

« previous php.internals (#94134) next »