Re: PHP File Upload Security Hole - Still No Fix?
| From: | Johan Andersson | Date: | Wed, 06 Sep 2000 13:50:19 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-32364@lists.php.net to get a copy of this message | ||
> Sheesh. Replace 'id' in example by 'title'. Redo from start.
> It was only an example. It wasn't real code.
>
Yeah.. but it's very different if you writes show.php?id=$row['id'] or
show.php?q=$searchstring
If you have an numeric id to lookup.. you just need to secure it's an numeric with
doing like:
$id = (int) $HTTP_GET_VARS['id'];