Re: New escaped output operator
| From: | Christoph Becker | Date: | Sun, 19 Jun 2016 18:42:39 +0000 |
| Subject: | Re: New escaped output operator | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94134@lists.php.net to get a copy of this message | ||
On 19.06.2016 at 19:28, Scott Arciszewski wrote:
> Further reading:
>
> https://paragonie.com/blog/2015/06/preventing-xss-vulnerabilities-in-php-everything-you-need-know
Thanks!
Minor issue:
| If you failed to specify ENT_QUOTES and attacker simply needs to pass
| " onload="malicious javascript code as a value to that form field and
| presto, instant client-side code execution.
That's not correct, unless ENT_NOQUOTES would have been specified. The
default of htmlspecialchars() is to escape double-quotes, but to leave
single-quotes alone.
--
Christoph M. Becker