Re: [RFC] Improve HTML escape

From: Date: Sun, 02 Feb 2014 03:15:00 +0000
Subject: Re: [RFC] Improve HTML escape
References: 1  Groups: php.internals 
Request: Send a blank email to [email protected] to get a copy of this message
On Sat, Feb 1, 2014 at 7:09 PM, Yasuo Ohgaki <[email protected]> wrote:
> This is a little improvement for HTML escape.
> https://wiki.php.net/rfc/secure-html-escape
>
> "/" escape is recommended by OWASP and we may follow them.
>
Could you include some samples of malicious input and what the output
would actually look like?  It's not obvious from the RFC or the link
referenced.

-Sara


Thread (37 messages)

« previous php.internals (#71969) next »