note 26221 added to function.strip-tags

From: Date: Tue, 22 Oct 2002 22:39:43 +0000
Subject: note 26221 added to function.strip-tags
Groups: php.notes 
Request: Send a blank email to php-notes+get-38438@lists.php.net to get a copy of this message
I'd like to note, that the code which removes SCRIPT tags with everything in them, as suggested by [mrmaxxx333 at triad dot rr dot com] and corrected then by [tim at e-matters dot de], doesn't work in the case when between the opening tag and the closing one a '<' is found. The whole block remains unchanged. To get around this, I changed the regex to the following: preg_replace('/<(script|style)[^>]*>.+<\/(script|style)[^>]*>/is', '', $cleaned_up_text); This one worked for me perfectly (it strips also STYLE blocks, if found). An additional interesting functionality of this regex, which I discovered, is that even overlapping blocks are being cleaned up, i.e. if you have One*<script language="blah">some malicious code; some more code; <style type="text/css">some html to try and confuse our regex</script> p { font-weight: bold; } </style dummy_flag>*Two after preg_replace'ing it, you'll remain with the string "One**Two" only. -- http://www.php.net/manual/en/function.strip-tags.php http://master.php.net/manage/user-notes.php?action=edit+26221 http://master.php.net/manage/user-notes.php?action=delete+26221 http://master.php.net/manage/user-notes.php?action=reject+26221

« previous php.notes (#38438) next »