Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Wed, 06 Sep 2000 13:43:57 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2 3 4 5 6 7 8 9 10 11  Groups: php.dev 
Request: Send a blank email to php-dev+get-32363@lists.php.net to get a copy of this message
You said to me that you didn't use htmlentities in url's .. but you just gave us another example of it .. As André said..An url is an url.. and that's not what htmlentities is for. That's what url_encode() is for. I think you have to look some further in the manual about the htmlentities, so you know when it should be used.. And using it in URLs in _NOT_ defensive programming! The encoding that should be on URLs is the following: Characters with ascii numbers 0-27, 127-255 should be replaced with [%][ascii number in hex] like %20 is space, space is ascii 32, which has the hexadecimal value 20. What htmlentities does is replacing html content such as special characters like < and > with &lt; and &gt; to make them visible when you really want to display such characters. I don't think I need to explain more.. Everything is in the RFCs ... Take RFC 1945 for example.. I think you'll find the definition of query strings there. And hey.. I just want to help you.. saw you wrote something incorrect and I just wanted to be nice and explain why I think you wrote something incorrect.. R, Johan Andersson > > > echo '<a > > > href="product.php?id=',htmlentities(urlencode($row['ID'])),'>'; > > > > > > (This is an excellent example of why I prefer H() and U() [;-)]

« previous php.dev (#32363) next »