RE: [PHP-DEV] PHP File Upload Security Hole - Still No Fix?
| From: | Gustafson, Mårten | Date: | Wed, 06 Sep 2000 10:35:11 +0000 |
| Subject: | RE: [PHP-DEV] PHP File Upload Security Hole - Still No Fix? | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-32340@lists.php.net to get a copy of this message | ||
> If you are writing code to produce HTML output, as I think I
> can safely assume most PHP code is, and you have never used
> htmlentities, then your code is almost certainly completely broken.
Not if your´re using a template system or some other technique to keep
application logic (PHP) and content (html) separated. I use such a system,
and in my current development tree there´s no occurrence of htmlentities().
And my code works, very well.
Marten.