Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Wed, 06 Sep 2000 14:17:34 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32371@lists.php.net to get a copy of this message | ||
Derick Rethans <d.rethans@jdimedia.nl> wrote:
> > is wrong. It should be:
> >
> > <a href="foo.php?a=1&b=2">
>
> This is bullshit.
No, it's a little-known fact.
> I never saw someone writing &.
I told you not a lot of people knew it.
> I don't see why it is wrong, or why it can be dangerous to use &.
If you don't believe me, simply try putting the following HTML page onto
a web server and try clicking on the links in a web browser.
<html><head><title>Foo</title></head>
<body>
<a href="foo?a=1&b=1">a=1&b=1</a><br>
<a href="foo?a=1&b=1">a=1&amp;b=1</a><br>
<a href="foo?a=1£=1">a=1&pound=1</a><br>
<a href="foo?a=1&pound=1">a=1&amp;pound=1</a><br>
</body></html>
If you don't understand why this is the case, try thinking about it for
a bit. It is not the server which decodes this - the server will indeed
receive 'a=1&b=1'. It is the *browser* which decodes the entity, just as
with any other entity it finds in an HTML document.