Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Wed, 06 Sep 2000 12:52:17 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32353@lists.php.net to get a copy of this message | ||
André Langhorst <waldschrott@php.net> wrote:
> > echo '<a
> > href="product.php?id=',htmlentities(urlencode($row['ID'])),'>';
> >
> > (This is an excellent example of why I prefer H() and U() [;-)]
>
> you´re designing crappy databases
Sorry, my database is crappy because it has a field named 'ID'? I don't
quite follow.
> and thus you have to apply functions no one else has to apply in those cases
No-one else has to output HTML? OK...
> (btw, you don´t need to apply htmlentities() after urlencode(), URL is URL
> there are no unescaped ><&"etc. signs in it)
Try this then:
echo '<a href="foo.php?',
htmlentities('a='.urlencode($a).'&b='.urlencode($b)),'">';
You are outputting HTML. You should call htmlentities whether or not
you are 99% sure you don't need it. It's called defensive programming
and it's a good idea.
> you don´t need to convert every single value which comes out of the
> database! theres a thing called database design.
And good database design says store all your values HTML-encoded?
News to me.
> btw, to do this on output is not performing well,
Most people these days seem to agree that writing readable and maintainable
code wins over miniscule performance increases.
> MOST sites are generating *much* more SELECTs than INSERTs or UPDATEs,
> thus convert on update and take care nobody touches your DB
That might be possible if you were in charge of all the code that updates
the databases. It's still horrible, even so.