<?php
$string = 'qwl=foobard47ae"style%3d"behavior%3aurl(%23default
%23time2)"onbegin%3d"alert(1)"79064c5e2bb&bar=foo';
$urlencoded = urlencode($string);
$urldecoded = urldecode($string);
var_dump($urlencoded);
var_dump($urldecoded);
var_dump(strip_tags($string));
var_dump(strip_tags($urlencoded));
var_dump(strip_tags($urldecoded));
- Output for 4.3.0 - 4.3.11, 4.4.0 - 4.4.9, 5.0.0 - 5.0.5, 5.1.0 - 5.1.6, 5.2.0 - 5.2.17, 5.3.0 - 5.3.29, 5.4.0 - 5.4.45, 5.5.0 - 5.5.38, 5.6.0 - 5.6.40, 7.0.0 - 7.0.33, 7.1.0 - 7.1.33, 7.2.0 - 7.2.33, 7.3.0 - 7.3.33, 7.4.0 - 7.4.33, 8.0.0 - 8.0.30, 8.1.0 - 8.1.28, 8.2.0 - 8.2.18, 8.3.0 - 8.3.6
- string(136) "qwl%3Dfoobard47ae%22style%253d%22behavior%253aurl%28%2523default%0A%2523time2%29%22onbegin%253d%22alert%281%29%2279064c5e2bb%26bar%3Dfoo"
string(90) "qwl=foobard47ae"style="behavior:url(#default
#time2)"onbegin="alert(1)"79064c5e2bb&bar=foo"
string(100) "qwl=foobard47ae"style%3d"behavior%3aurl(%23default
%23time2)"onbegin%3d"alert(1)"79064c5e2bb&bar=foo"
string(136) "qwl%3Dfoobard47ae%22style%253d%22behavior%253aurl%28%2523default%0A%2523time2%29%22onbegin%253d%22alert%281%29%2279064c5e2bb%26bar%3Dfoo"
string(90) "qwl=foobard47ae"style="behavior:url(#default
#time2)"onbegin="alert(1)"79064c5e2bb&bar=foo"
preferences:
330.18 ms | 407 KiB | 460 Q