vendor:
PHP
by:
Unknown
N/A
CVSS
MEDIUM
HTML Injection
79
CWE
Product Name: PHP
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Windows, Linux, Mac
Unknown
Bypass PHP’s strip_tags() Function
Under certain circumstances, PHP's strip_tags() function improperly leaves malformed tags in place, allowing for potential cross-site scripting and HTML injection vulnerabilities when viewed by Microsoft Internet Explorer or Apple Safari web browsers.
Mitigation:
Ensure 'magic_quotes_gpc' is enabled in PHP configuration.