If you "remove HTML" with a regex like that, then I can still get whatever HTML I want in like so:
<a <b>href="www.example.com">Cheap Viagra!</</b>a> <script<b>> alert("CHEAP VIAGRA!") </script</b>>
Escaping is a much better idea.
- tye
In reply to Re^2: Code does Remove Html (hole)
by tye
in thread Code does Remove Html
by Anonymous Monk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |