From 9959fedc755786c34cb5a671443701e8f2885617 Mon Sep 17 00:00:00 2001
From: Derek Jones
Date: Wed, 4 Feb 2009 20:37:40 +0000
Subject: improvements to xss_clean()
---
system/libraries/Input.php | 11 ++++++-----
user_guide/changelog.html | 1 +
2 files changed, 7 insertions(+), 5 deletions(-)
diff --git a/system/libraries/Input.php b/system/libraries/Input.php
index 347aac3ac..e879e2d13 100644
--- a/system/libraries/Input.php
+++ b/system/libraries/Input.php
@@ -47,9 +47,10 @@ class CI_Input {
);
/* never allowed, regex replacement */
var $never_allowed_regex = array(
- "javascript\s*:" => '[removed]',
- "expression\s*\(" => '[removed]', // CSS and IE
- "Redirect\s+302" => '[removed]'
+ "javascript\s*:" => '[removed]',
+ "expression\s*(\(|&\#40;)" => '[removed]', // CSS and IE
+ "vbscript\s*:" => '[removed]', // IE, surprise!
+ "Redirect\s+302" => '[removed]'
);
/**
@@ -946,7 +947,7 @@ class CI_Input {
*/
function _convert_attribute($match)
{
- return str_replace(array('>', '<'), array('>', '<'), $match[0]);
+ return str_replace(array('>', '<', '\\'), array('>', '<', '\\\\'), $match[0]);
}
// --------------------------------------------------------------------
@@ -1043,7 +1044,7 @@ class CI_Input {
{
foreach ($matches[0] as $match)
{
- $out .= "{$match}";
+ $out .= preg_replace("#/\*.*?\*/#s", '', $match);
}
}
diff --git a/user_guide/changelog.html b/user_guide/changelog.html
index 6c32f5071..43059397b 100644
--- a/user_guide/changelog.html
+++ b/user_guide/changelog.html
@@ -88,6 +88,7 @@ SVN Revision:
Other Changes
+ - Improved security in xss_clean().
- Added 'application/msexcel' to config/mimes.php for .xls files.
--
cgit v1.2.3-24-g4f1b