From: Scott MacVicar Date: Tue, 15 Jul 2008 14:58:58 +0000 (+0000) Subject: MFH: Fix bug when < is used within attribute. X-Git-Tag: php-5.2.7RC1~204 X-Git-Url: https://granicus.if.org/sourcecode?a=commitdiff_plain;h=56f7e28f5ddfa5c3e7f18b4884ec473f0725586d;p=php MFH: Fix bug when < is used within attribute. --- diff --git a/NEWS b/NEWS index 1c5be1ea4d..450dcfdf7d 100644 --- a/NEWS +++ b/NEWS @@ -9,6 +9,7 @@ PHP NEWS - Fixed a crash inside PDO when trying instantiate PDORow manually. (Felipe) - Fixed build failure of ext/mysqli with libmysql 6.0 - missing rpl functions. (Andrey) +- Fixed a regression when using strip_tags() and < is within an attribute. (Scott) - Fixed bug #45486 (mb_send_mail(); header 'Content-Type: text/plain; charset=' parsing incorrect). (Felipe) diff --git a/ext/standard/string.c b/ext/standard/string.c index 54f680a00d..e038bc7ba7 100644 --- a/ext/standard/string.c +++ b/ext/standard/string.c @@ -4355,6 +4355,9 @@ PHPAPI size_t php_strip_tags_ex(char *rbuf, int len, int *stateptr, char *allow, case '\0': break; case '<': + if (in_q) { + break; + } if (isspace(*(p + 1)) && !allow_tag_spaces) { goto reg_char; } diff --git a/ext/standard/tests/strings/strip_tags_variation11.phpt b/ext/standard/tests/strings/strip_tags_variation11.phpt new file mode 100644 index 0000000000..3b47b5c6b1 --- /dev/null +++ b/ext/standard/tests/strings/strip_tags_variation11.phpt @@ -0,0 +1,41 @@ +--TEST-- +Test strip_tags() function : obscure values within attributes +--INI-- +short_open_tag = on +--FILE-- + world', + 'hello world', + 'hello world', + "hello world" +); + + +// Calling strip_tags() with default arguments +// loop through the $string_array to test strip_tags on various inputs +$iteration = 1; +foreach($string_array as $string) +{ + echo "-- Iteration $iteration --\n"; + var_dump( strip_tags($string) ); + $iteration++; +} + +echo "Done"; +?> +--EXPECTF-- +*** Testing strip_tags() : obscure functionality *** +-- Iteration 1 -- +string(12) "hello world" +-- Iteration 2 -- +string(12) "hello world" +-- Iteration 3 -- +string(12) "hello world" +-- Iteration 4 -- +string(12) "hello world" +Done