note 68667 added to ref.simplexml
| From: | RowanLewis at osu1 dot php dot net | Date: | Sun, 06 Aug 2006 06:12:29 +0000 |
| Subject: | note 68667 added to ref.simplexml | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-115579@lists.php.net to get a copy of this message | ||
Unfortunately for a project I was writing which used Tidy and SimpleXML to grant complete control to
the developer over and HTML content passed by users, SimpleXML doesn't maintain the original
structure of the input.
What I mean by this is that when you use AsXML() to grab the XML of an element, if the element
contains children other than text, SimpleXML changes the indentation.
So any code like this:
<a href="java script:alert('1');"><b>Item Two</b></a>
Will come out like this:
<a href="java script:alert('1');">
<b>Item Two</b>
</a>
Which, if you are using a find/replace routine, will cause it to fail. In our case, it caused it to
fail, and pass malicious code.
----
Server IP: 66.163.161.117
Probable Submitter: 58.108.39.116
----
X-Spam-Status: No, hits=4.0 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER,
HTML_20_30,HTML_MESSAGE autolearn=no version=2.64
----
Manual Page -- http://www.php.net/manual/en/ref.simplexml.php
Edit -- https://master.php.net/note/edit/68667
Del: integrated -- https://master.php.net/note/delete/68667/integrated
Del: useless -- https://master.php.net/note/delete/68667/useless
Del: bad code -- https://master.php.net/note/delete/68667/bad+code
Del: spam -- https://master.php.net/note/delete/68667/spam
Del: non-english -- https://master.php.net/note/delete/68667/non-english
Del: in docs -- https://master.php.net/note/delete/68667/in+docs
Del: other reasons-- https://master.php.net/note/delete/68667
Reject -- https://master.php.net/note/reject/68667
Search -- https://master.php.net/manage/user-notes.php