Re: PHP File Upload Security Hole - Still No Fix?
| From: | Derick Rethans | Date: | Wed, 06 Sep 2000 14:05:38 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32370@lists.php.net to get a copy of this message | ||
Jon Ribbens wrote:
>
> <a href="foo.php?a=1&b=2">
>
> is wrong. It should be:
>
> <a href="foo.php?a=1&b=2">
>
This is bullshit. I never saw someone writing &. These entities are for
DISPLAYING html entities.
I don't see why it is wrong, or why it can be dangerous to use &.
Following your reasons,
<a href="foo.php?a=1&b=2">
is wrong too, it has to be:
<a href="foo.php?a=1&b=2">
or maybe
<a href=\"foo.php?a=1&b=2\">
just te be sure.
Derick Rethans