mirror of
https://github.com/Xkeeper0/jul.git
synced 2025-05-19 00:30:21 -07:00
Merge pull request #48 from RanAwaySuccessfully/patch-1
fixing xss-blocking regex bug
This commit is contained in:
commit
5dfc60ce91
@ -1263,7 +1263,7 @@ function xss_clean($data) {
|
||||
#$data = preg_replace('#(<[^>]+?[\x00-\x20"\'])(?:on|xmlns)[^>]*+>#iu', '$1>', $data);
|
||||
do {
|
||||
$old_data = $data;
|
||||
$data = preg_replace('#(<[^>]+?[\x00-\x20"\'])(on|xmlns)([^>]*+)>#iu', '$1DISABLED_$2$3>', $data);
|
||||
$data = preg_replace('#(<[A-Za-z][^>]*?[\x00-\x20"\'])(on|xmlns)([^>]*+)>#iu', '$1DISABLED_$2$3>', $data);
|
||||
} while ($old_data !== $data);
|
||||
|
||||
// Remove javascript: and vbscript: protocols
|
||||
|
Loading…
x
Reference in New Issue
Block a user