diff --git a/includes/common.inc b/includes/common.inc index ca717e5064a050557125b4de35125ba68216ae68..3ebfa13c0ba7e84864545c3761e3e7d40862d2d7 100644 --- a/includes/common.inc +++ b/includes/common.inc @@ -484,12 +484,13 @@ function xss_check_input_data($data) { */ // check strings: - $match += preg_match("/\Wjavascript\s*:/i", $data); + $match = preg_match("/\Wjavascript\s*:/i", $data); $match += preg_match("/\Wexpression\s*\(/i", $data); $match += preg_match("/\Walert\s*\(/i", $data); // check attributes: - $match = preg_match("/\W(dynsrc|datasrc|data|lowsrc|on[a-z]+)\s*=[^>]+?>/i", $data); + $match += preg_match("/\W(dynsrc|datasrc|data|lowsrc|on[a-z]+)\s*=[^>]+?>/i", $data); + // check tags: $match += preg_match("/<\s*(applet|script|object|style|embed|form|blink|meta|html|frame|iframe|layer|ilayer|head|frameset|xml)/i", $data);