summaryrefslogtreecommitdiffstats
path: root/system/core/Security.php
diff options
context:
space:
mode:
Diffstat (limited to 'system/core/Security.php')
-rw-r--r--system/core/Security.php2
1 files changed, 1 insertions, 1 deletions
diff --git a/system/core/Security.php b/system/core/Security.php
index 829aac7d2..ca0991ac4 100644
--- a/system/core/Security.php
+++ b/system/core/Security.php
@@ -795,7 +795,7 @@ class CI_Security {
.')*' // end optional attributes group
.')' // end catching evil attribute prefix
// evil attribute starts here
- .'([\s\042\047>/=]+' // non-attribute characters (we'll replace that with a single space)
+ .'([\s\042\047/=]+' // non-attribute characters (we'll replace that with a single space), again excluding '>'
.'('.implode('|', $evil_attributes).')'
.'\s*=\s*' // attribute-value separator
.'(\042[^042]+\042|\047[^047]+\047|[^\s\042\047=><`]+)' // attribute value; single, double or non-quotes