Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Wed, 06 Sep 2000 12:52:17 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2 3 4 5 6 7 8 9 10  Groups: php.dev 
Request: Send a blank email to php-dev+get-32353@lists.php.net to get a copy of this message
André Langhorst <waldschrott@php.net> wrote: > > echo '<a > > href="product.php?id=',htmlentities(urlencode($row['ID'])),'>'; > > > > (This is an excellent example of why I prefer H() and U() [;-)] > > you´re designing crappy databases Sorry, my database is crappy because it has a field named 'ID'? I don't quite follow. > and thus you have to apply functions no one else has to apply in those cases No-one else has to output HTML? OK... > (btw, you don´t need to apply htmlentities() after urlencode(), URL is URL > there are no unescaped ><&"etc. signs in it) Try this then: echo '<a href="foo.php?', htmlentities('a='.urlencode($a).'&b='.urlencode($b)),'">'; You are outputting HTML. You should call htmlentities whether or not you are 99% sure you don't need it. It's called defensive programming and it's a good idea. > you don´t need to convert every single value which comes out of the > database! theres a thing called database design. And good database design says store all your values HTML-encoded? News to me. > btw, to do this on output is not performing well, Most people these days seem to agree that writing readable and maintainable code wins over miniscule performance increases. > MOST sites are generating *much* more SELECTs than INSERTs or UPDATEs, > thus convert on update and take care nobody touches your DB That might be possible if you were in charge of all the code that updates the databases. It's still horrible, even so.

« previous php.dev (#32353) next »