in reply to Emergency! Our guestbook is getting trashed by HTML!
Setting $allow_html to 0 will *attempt* to remove HTML. It will fail if the person supplies a < without a matching >. Fixing it would be convoluted. It's easier to just escape < and >:
if ($allow_html != 1) { $value =~ s/</</g; $value =~ s/>/>/g; }
Better yet, have a look at secure versions of Matt's scripts.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Emergency! Our guestbook is getting trashed by HTML!
by amw1 (Friar) on Dec 17, 2004 at 16:53 UTC | |
by manwhore (Initiate) on Jan 07, 2005 at 22:49 UTC |