Re: The man-that-makes-me-sick returns (Was: PHP File Upload Security Hole - Still No Fix?)
| From: | Hellekin O. Wolf | Date: | Wed, 06 Sep 2000 15:10:37 +0000 |
| Subject: | Re: The man-that-makes-me-sick returns (Was: PHP File Upload Security Hole - Still No Fix?) | ||
| References: | 1 2 3 4 5 6 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32390@lists.php.net to get a copy of this message | ||
Jon Ribbens wrote:
>
> Derick Rethans <d.rethans@jdimedia.nl> wrote:
> > For me, I will never use "pound" as a varaible name now.
>
> Umm... You *are* joking here aren't you? ;-)
>
*** Indeed he meant to say "I won't use any HTML entity as a PHP
variable", didn't you Derick ?
Those are well-known and not so many... Indeed, if your $myvar becomes
an HTML entity, then you have to rewrite your code to escape all
"&myvar" from it and Jon is right in saying that you should
htmlentities($your_query)... (You also have to blame w3c ;-)
Maybe it would be a good point to take into account concerning PEAR.
Although I don't see why a PEAR class would pass arguments in an URL...
but who knows.
hellekin