note 26221 added to function.strip-tags
| From: | interdist at rack1 dot php dot net | Date: | Tue, 22 Oct 2002 22:39:43 +0000 |
| Subject: | note 26221 added to function.strip-tags | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-38438@lists.php.net to get a copy of this message | ||
I'd like to note, that the code which removes SCRIPT tags with everything in them, as suggested
by [mrmaxxx333 at triad dot rr dot com] and corrected then by [tim at e-matters dot de],
doesn't work in the case when between the opening tag and the closing one a '<' is
found. The whole block remains unchanged.
To get around this, I changed the regex to the following:
preg_replace('/<(script|style)[^>]*>.+<\/(script|style)[^>]*>/is',
'', $cleaned_up_text);
This one worked for me perfectly (it strips also STYLE blocks, if found). An additional interesting
functionality of this regex, which I discovered, is that even overlapping blocks are being cleaned
up, i.e. if you have
One*<script language="blah">some malicious code; some more code; <style
type="text/css">some html to try and confuse our regex</script> p { font-weight:
bold; } </style dummy_flag>*Two
after preg_replace'ing it, you'll remain with the string "One**Two" only.
--
http://www.php.net/manual/en/function.strip-tags.php
http://master.php.net/manage/user-notes.php?action=edit+26221
http://master.php.net/manage/user-notes.php?action=delete+26221
http://master.php.net/manage/user-notes.php?action=reject+26221