note 68667 added to ref.simplexml

From: Date: Sun, 06 Aug 2006 06:12:29 +0000
Subject: note 68667 added to ref.simplexml
Groups: php.notes 
Request: Send a blank email to php-notes+get-115579@lists.php.net to get a copy of this message
Unfortunately for a project I was writing which used Tidy and SimpleXML to grant complete control to the developer over and HTML content passed by users, SimpleXML doesn't maintain the original structure of the input. What I mean by this is that when you use AsXML() to grab the XML of an element, if the element contains children other than text, SimpleXML changes the indentation. So any code like this: <a href="java script:alert('1');"><b>Item Two</b></a> Will come out like this: <a href="java script:alert('1');"> <b>Item Two</b> </a> Which, if you are using a find/replace routine, will cause it to fail. In our case, it caused it to fail, and pass malicious code. ---- Server IP: 66.163.161.117 Probable Submitter: 58.108.39.116 ---- X-Spam-Status: No, hits=4.0 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER, HTML_20_30,HTML_MESSAGE autolearn=no version=2.64 ---- Manual Page -- http://www.php.net/manual/en/ref.simplexml.php Edit -- https://master.php.net/note/edit/68667 Del: integrated -- https://master.php.net/note/delete/68667/integrated Del: useless -- https://master.php.net/note/delete/68667/useless Del: bad code -- https://master.php.net/note/delete/68667/bad+code Del: spam -- https://master.php.net/note/delete/68667/spam Del: non-english -- https://master.php.net/note/delete/68667/non-english Del: in docs -- https://master.php.net/note/delete/68667/in+docs Del: other reasons-- https://master.php.net/note/delete/68667 Reject -- https://master.php.net/note/reject/68667 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#115579) next »