If using an HTML whitelist and HTMLPurifier, are there any shenanigans a malicious user can execute if <a></a> is allo开发者_JAVA百科wed?
For atmosphere:

Not if you only allow the href attribute and don't allow the javascript: pseudo protocol.
If using an HTML whitelist and HTMLPurifier, are there any shenanigans a malicious user can execute if <a></a> is allo开发者_JAVA百科wed?
For atmosphere:

Not if you only allow the href attribute and don't allow the javascript: pseudo protocol.
精彩评论