note 51451 deleted from function.htmlentities by betz

From: Date: Thu, 31 Mar 2005 11:48:12 +0000
Subject: note 51451 deleted from function.htmlentities by betz
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-87256@lists.php.net to get a copy of this message
Note Submitter: jasperbg at gmail dot com ---- art at zollerwagner dot com: You DO need to htmlentities() data that you will be placing in a textarea field. Imagine that a user were to submit the following data to be placed in the field: </textarea> <script type="text/javascript" src="[some evil script here]"></script> <textarea> If you didn't htmlentities() the data, that would close the textarea, include the user's potentially malicious script, and then open a new textarea (optional, but preserves code validity). A classic XSS attack.

« previous php.notes (#87256) next »