#5640: Sanitize::stripScripts also removes image tags
--------------------------+-------------------------------------------------
    Reporter:  tyler      |         Owner:         
        Type:  Bug        |        Status:  closed 
    Priority:  Low        |     Milestone:  1.2.x.x
   Component:  Core Libs  |       Version:  RC3    
    Severity:  Minor      |    Resolution:  invalid
    Keywords:             |   Php_version:  PHP 5  
Cake_version:             |  
--------------------------+-------------------------------------------------
Changes (by mark_story):

  * status:  new => closed
  * resolution:  => invalid

Comment:

 This is intentional.  You can perform XSS through the src attribute of an
 img tag.

-- 
Ticket URL: <https://trac.cakephp.org/ticket/5640#comment:1>
CakePHP : The Rapid Development Framework for PHP <https://trac.cakephp.org/>
Cake is a rapid development framework for PHP which uses commonly known design 
patterns like ActiveRecord, Association Data Mapping, Front Controller and MVC. 
Our primary goal is to provide a structured framework that enables PHP users at 
all levels to rapidly develop robust web applications, without any loss to 
flexibility.
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"tickets cakephp" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at 
http://groups.google.com/group/tickets-cakephp?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to