Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Wed, 06 Sep 2000 14:17:34 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2 3 4 5 6 7 8 9 10  Groups: php.dev 
Request: Send a blank email to php-dev+get-32371@lists.php.net to get a copy of this message
Derick Rethans <d.rethans@jdimedia.nl> wrote: > > is wrong. It should be: > > > > <a href="foo.php?a=1&amp;b=2"> > > This is bullshit. No, it's a little-known fact. > I never saw someone writing &amp;. I told you not a lot of people knew it. > I don't see why it is wrong, or why it can be dangerous to use &. If you don't believe me, simply try putting the following HTML page onto a web server and try clicking on the links in a web browser. <html><head><title>Foo</title></head> <body> <a href="foo?a=1&b=1">a=1&amp;b=1</a><br> <a href="foo?a=1&amp;b=1">a=1&amp;amp;b=1</a><br> <a href="foo?a=1&pound=1">a=1&amp;pound=1</a><br> <a href="foo?a=1&amp;pound=1">a=1&amp;amp;pound=1</a><br> </body></html> If you don't understand why this is the case, try thinking about it for a bit. It is not the server which decodes this - the server will indeed receive 'a=1&b=1'. It is the *browser* which decodes the entity, just as with any other entity it finds in an HTML document.

« previous php.dev (#32371) next »