HTML sanitization: Difference between revisions

Content deleted Content added
Added suggestion to use PHP htmlspecialchars()
this does not prevent SQL injection at all
Line 1:
{{Orphan|date=December 2009}}
{{Refimprove|date=December 2009}}
'''HTML sanitization''' is the process of examining an HTML document and producing a new HTML document that preserves only whatever tags are designated "safe". HTML sanitization can be used to protect against [[cross-site scripting]] and [[SQL injection]] attacks by sanitizing any HTML code submitted by a user.
 
Tags often allowed are <nowiki><b></nowiki>, <nowiki><i></nowiki>, <nowiki><u></nowiki>, <nowiki><em></nowiki>, and <nowiki><strong></nowiki>.