Is there a definitive anti-XSS library for PHP?

后端 未结 7 2192
长发绾君心
长发绾君心 2020-12-14 08:14

I already know how XSS works, but finding out all the many different ways to inject malicious input is not an option.

I saw a couple libraries out there, but most of

7条回答
  •  暗喜
    暗喜 (楼主)
    2020-12-14 08:43

    In addition to zerkms's answer, if you find you need to accept user submitted HTML (from a WYSIWYG editor, for example), you will need to use a HTML parser to determine what can and can't be submitted.

    I use and recommend HTML Purifier.

    Note: Don't even try to use regex :)

提交回复
热议问题