Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Tue, 05 Sep 2000 12:53:01 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-32140@lists.php.net to get a copy of this message
Zeev Suraski <zeev@zend.com> wrote: > I fully agree that using register_globals is a bad idea, and a bad > concept. This is one of the reasons i made track_vars on by default for > PHP 4.0, and personally encourage people to use these arrays, and have > register_globals turned off. Can I suggest that adding in a concise syntax to access the variables would be an excellent idea? People are never going to sit there typing '$HTTP_POST_VARS' all the way through their script. Yes, you can add in a function in a library, but a lot of people aren't going to do that (and PHP's philosophy appears to be to put everything built-in anyway ;-) ). If you had a '%var' syntax, or a built-in function with a very short name, I think this would help immensely.

« previous php.dev (#32140) next »