Re: cvs: pear /XML_Transformer Transformer.php

From: Date: Thu, 16 Jan 2003 18:24:47 +0000
Subject: Re: cvs: pear /XML_Transformer Transformer.php
References: 1 2 3  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-12545@lists.php.net to get a copy of this message
Kristian Koehntopp schrieb: > No, because that is never parsed as a PI, and in the case > of PHP is never > executed. If havn't parsing on the server in mind only. What happens, if JavaScript (<?javascript) or something is embedded in the XML? This will passed to the client - i'm not sure, if IE can parse this already. Currently, the most guestbook&co apps check for javascript in the text, but who checks for malicious PIs in XML? You are right with my propose, the user can use eval($data) - but unexpected PIs are dropped automatically. PS: A user could also do eval($cdata)... > Autobahn for > stupidity. Instead you hope, the user checks every CDATA section for unexpected PIs? :-)

« previous php.pear.dev (#12545) next »