Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Wed, 06 Sep 2000 14:40:07 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2 3 4 5 6 7 8 9 10 11  Groups: php.dev 
Request: Send a blank email to php-dev+get-32384@lists.php.net to get a copy of this message
Jon Ribbens wrote: > > <html><head><title>Foo</title></head> > <body> > <a href="foo?a=1&b=1">a=1&amp;b=1</a><br> > <a href="foo?a=1&amp;b=1">a=1&amp;amp;b=1</a><br> > <a href="foo?a=1&pound=1">a=1&amp;pound=1</a><br> > <a href="foo?a=1&amp;pound=1">a=1&amp;amp;pound=1</a><br> > </body></html> > *** Neat... Indeed it makes a difference. £ is not &pound AFAIK. I've been reading the whole thread with interest. Many points have been raised that are important but they're so much surrounded by dirt that maybe you Jon, as you started this whole comment, should filter it and come with some (objective) synthesis that could encourage other people to pay attention to what you have to say. That said, I'm always surprised with comments such as "this is bad style programming" that takes for granted that every programmer knows "how to program well". I'm sorry to tell you guyz, everybody starts from zero and acquire experience through learning and practiving. Good coding style is not obvious and indeed seem to depend on the programmer's background also. Such a discussion is important and may be helpful for most of us, PHP programmers, experts or beginners, to learn how to avoid Bad Coding Practice (TM). can't we all get along ? ;-) hellekin

« previous php.dev (#32384) next »