Re: The man-that-makes-me-sick returns (Was: PHP File Upload Security Hole - Still No Fix?)

From: Date: Wed, 06 Sep 2000 15:10:37 +0000
Subject: Re: The man-that-makes-me-sick returns (Was: PHP File Upload Security Hole - Still No Fix?)
References: 1 2 3 4 5 6  Groups: php.dev 
Request: Send a blank email to php-dev+get-32390@lists.php.net to get a copy of this message
Jon Ribbens wrote: > > Derick Rethans <d.rethans@jdimedia.nl> wrote: > > For me, I will never use "pound" as a varaible name now. > > Umm... You *are* joking here aren't you? ;-) > *** Indeed he meant to say "I won't use any HTML entity as a PHP variable", didn't you Derick ? Those are well-known and not so many... Indeed, if your $myvar becomes an HTML entity, then you have to rewrite your code to escape all "&myvar" from it and Jon is right in saying that you should htmlentities($your_query)... (You also have to blame w3c ;-) Maybe it would be a good point to take into account concerning PEAR. Although I don't see why a PEAR class would pass arguments in an URL... but who knows. hellekin

« previous php.dev (#32390) next »