Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Wed, 06 Sep 2000 14:05:38 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2 3 4 5 6 7 8 9 10 11  Groups: php.dev 
Request: Send a blank email to php-dev+get-32370@lists.php.net to get a copy of this message
Jon Ribbens wrote: > > <a href="foo.php?a=1&b=2"> > > is wrong. It should be: > > <a href="foo.php?a=1&amp;b=2"> > This is bullshit. I never saw someone writing &amp;. These entities are for DISPLAYING html entities. I don't see why it is wrong, or why it can be dangerous to use &. Following your reasons, <a href="foo.php?a=1&amp;b=2"> is wrong too, it has to be: &lt;a href="foo.php?a=1&amp;b=2"&gt; or maybe &lt;a href=\"foo.php?a=1&amp;b=2\"&gt; just te be sure. Derick Rethans

« previous php.dev (#32370) next »