Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Wed, 06 Sep 2000 10:39:55 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32341@lists.php.net to get a copy of this message | ||
"\"Gustafson, Mårten\"" <marten@jerbro.se> wrote:
> Not if your´re using a template system or some other technique to keep
> application logic (PHP) and content (html) separated. I use such a system,
> and in my current development tree there´s no occurrence of htmlentities().
> And my code works, very well.
Yes, I suppose I should have excluded the case whereby you already have
abstracted htmlentities into a separate function. But, as I have already
repeatedly mentioned, the PHP philosophy seems to be to put everything
possible into the PHP C code itself, rather than in separate libraries.