Re: PHP File Upload Security Hole - Still No Fix?
| From: | Chuck Hagenbuch | Date: | Tue, 05 Sep 2000 14:30:34 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32179@lists.php.net to get a copy of this message | ||
Quoting Jon Ribbens <jon+php-dev@unequivocal.co.uk>:
> addslashes (which should also add the single quotes at the beginning and
> the end like $dbh->quote() in Perl)
Why?
I'm open to the idea that you might have something useful to contribute, but
you seem to make a lot of assumptions based on your specific coding style.
That change might save you a few characters of typing, but it would actually
make addslashes() _less_ flexible. And given the two choices, I would choose
the current behavior - it is easier to add on a few quotes to the result of
addslashes() than it would be to strip them off every time you didn't want
them.
-chuck
--
Charles Hagenbuch, <chuck@horde.org>
--
Hockey means never having to say you're sorry.