note 51451 deleted from function.htmlentities by betz
| From: | betz@php.net | Date: | Thu, 31 Mar 2005 11:48:12 +0000 |
| Subject: | note 51451 deleted from function.htmlentities by betz | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-87256@lists.php.net to get a copy of this message | ||
Note Submitter: jasperbg at gmail dot com
----
art at zollerwagner dot com:
You DO need to htmlentities() data that you will be placing in a textarea field.
Imagine that a user were to submit the following data to be placed in the field:
</textarea>
<script type="text/javascript" src="[some evil script
here]"></script>
<textarea>
If you didn't htmlentities() the data, that would close the textarea, include the user's
potentially malicious script, and then open a new textarea (optional, but preserves code validity).
A classic XSS attack.