note 33993 added to function.strip-tags

From: Date: Sun, 13 Jul 2003 00:45:04 +0000
Subject: note 33993 added to function.strip-tags
Groups: php.notes 
Request: Send a blank email to php-notes+get-51997@lists.php.net to get a copy of this message
Judging from the sheer number of "holes" found in the posted samples, clearly, creating "safe" html is a difficult task. Consider an alternative (html to text) from Tom: http://www.perl.com/CPAN/authors/Tom_Christiansen/scripts/striphtml.gz FYI, I noticed that no one has yet reported a flaw in inputCheck() from charlieNOSPAM's. It missed the case: <img src="http://.com/transparent.gif" width=300 height=300 onmouseover="alert('hello')" By dropping the trailing '>', the tag isn't uppercased, and then fails to match the rule (supposing that "IMG" was added to the list of tags to disable). Most badhtml2safehtml() functions seem to miss the possibility of mixed case in the tags name, dangerous attributes, or malformed HTML that still executes something dangerous in a forgiving web browser. ---- Manual Page -- http://www.php.net/manual/en/function.strip-tags.php Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+33993 Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+33993&report=yes Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+33993&report=yes

« previous php.notes (#51997) next »