Re: cvs: pear /XML_Transformer Transformer.php
| From: | alexander dot merz at t-online dot de | Date: | Thu, 16 Jan 2003 18:24:47 +0000 |
| Subject: | Re: cvs: pear /XML_Transformer Transformer.php | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-12545@lists.php.net to get a copy of this message | ||
Kristian Koehntopp schrieb:
> No, because that is never parsed as a PI, and in the case
> of PHP is never
> executed.
If havn't parsing on the server in mind only.
What happens, if JavaScript (<?javascript) or something is embedded in
the XML?
This will passed to the client - i'm not sure, if IE can parse this
already.
Currently, the most guestbook&co apps check for javascript in the text,
but who checks for malicious PIs in XML?
You are right with my propose, the user can use eval($data) - but
unexpected PIs are dropped automatically. PS: A user could also do
eval($cdata)...
> Autobahn for
> stupidity.
Instead you hope, the user checks every CDATA section for unexpected
PIs? :-)