Description
Encodes an input string for a safe HTML output to prevent Cross Site Scripting (XSS) attacks.
Returns
Encoded string
Category
Display and formatting functions
Syntax
Description
Encodes an input string for a safe HTML output to prevent Cross Site Scripting (XSS) attacks.
Encoded string
Display and formatting functions
encodeForHTML(inputString [,canonicalize])
See also
Canonicalize, EncodeForHTMLAttribute, EncodeForJavaScript, EncodeForCSS, EncodeForURL
ColdFusion 10: Added this function.
Parameter |
Description |
---|---|
inputString |
Required. The string to encode. |
canonicalize |
Optional. If set to true, canonicalization happens before encoding. If set to false, the given input string will just be encoded. The default value for |
<cfscript> s1="<script>"; s2="&<>'/" & '"'; WriteOutput(EncodeForHTML(s1) & " | "); WriteOutput(EncodeForHTML(s2)); </cfscript>