note 12533 deleted from function.strip-tags by jimw
| From: | jimw@php.net | Date: | Mon, 29 Oct 2001 01:52:44 +0000 |
| Subject: | note 12533 deleted from function.strip-tags by jimw | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-19553@lists.php.net to get a copy of this message | ||
Re:david@surffactory.se and his comments about strip_tags() allowing event handlers and other extra
attributes, it seems (on the version 4.0.3pl1 of php at least) that brackets are now stripped out of
any javascript. So the for loop and window.open in his example would be disarmed.
However, assignments and the like are still allowed. For instance, document.location.href could be
set to a new location onmouseover, or variables used in javascript elsewhere on the page could be
set to unexpected values.
Also worth noting is the fact that text-formatting tags such as <I> could be left open so that
the malicious mouseover would effect any following text on rest of the page.