Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Wed, 06 Sep 2000 11:04:49 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-32343@lists.php.net to get a copy of this message
Dito. And my code is working very well too. But I think the template programming model has nothing to do with htmlentities(). Since htmlentities is to "escape" HTML code from a variable or content given to the function. In my case where I use it at most is in like guestbooks, walls etc., where I don't want the user be able to use HTML. Of course you can solve _that_ problem in another way with a simple regexp (ie. /<[^>]*>/) to remove the html tags.. but that's another issue. Just wanted to say that templates is not instead of the use of htmlentities(), and the code could work very well without either of these functionalities. And I just wonders why do you, Ribbens, use htmlentities() in case of building up an URL. . ? You might want to url encode a search query etc. but that's url_encode, isn't it? Just asking.. R, Johan Andersson ----- Original Message ----- From: Gustafson, Mårten <marten@jerbro.se> To: <php-dev@lists.php.net> Cc: 'Jon Ribbens' <jon+php-dev@unequivocal.co.uk> Sent: Wednesday, September 06, 2000 12:35 PM Subject: RE: [PHP-DEV] PHP File Upload Security Hole - Still No Fix? > If you are writing code to produce HTML output, as I think I > can safely assume most PHP code is, and you have never used > htmlentities, then your code is almost certainly completely broken. Not if your´re using a template system or some other technique to keep application logic (PHP) and content (html) separated. I use such a system, and in my current development tree there´s no occurrence of htmlentities(). And my code works, very well. Marten. -- PHP Development Mailing List <http://www.php.net/> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net For additional commands, e-mail: php-dev-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.dev (#32343) next »