Re: PHP File Upload Security Hole - Still No Fix?
| From: | Johan Andersson | Date: | Wed, 06 Sep 2000 13:43:57 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32363@lists.php.net to get a copy of this message | ||
You said to me that you didn't use htmlentities in url's .. but you just gave us
another example of it ..
As André said..An url is an url.. and that's not what htmlentities is for.
That's what url_encode() is for.
I think you have to look some further in the manual about the htmlentities,
so you know when it should be used.. And using it in URLs in _NOT_
defensive programming!
The encoding that should be on URLs is the following:
Characters with ascii numbers 0-27, 127-255 should be replaced with
[%][ascii number in hex]
like %20 is space, space is ascii 32, which has the hexadecimal value 20.
What htmlentities does is replacing html content such as special characters like
< and > with < and > to make them visible when you really want to display
such characters. I don't think I need to explain more..
Everything is in the RFCs ... Take RFC 1945 for example.. I think you'll find
the definition of query strings there.
And hey.. I just want to help you.. saw you wrote something incorrect and I
just wanted to be nice and explain why I think you wrote something incorrect..
R,
Johan Andersson
> > > echo '<a
> > > href="product.php?id=',htmlentities(urlencode($row['ID'])),'>';
> > >
> > > (This is an excellent example of why I prefer H() and U() [;-)]