Re: The man-that-makes-me-sick returns (Was: PHP File Upload Security Hole - Still No Fix?)
| From: | Derick Rethans | Date: | Wed, 06 Sep 2000 15:19:20 +0000 |
| Subject: | Re: The man-that-makes-me-sick returns (Was: PHP File Upload Security Hole - Still No Fix?) | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32393@lists.php.net to get a copy of this message | ||
"Hellekin O. Wolf" wrote:
> Jon Ribbens wrote:
> >
> > Derick Rethans <d.rethans@jdimedia.nl> wrote:
> > > For me, I will never use "pound" as a varaible name now.
> >
> > Umm... You *are* joking here aren't you? ;-)
No, I actually wasn't :)
>
> >
> *** Indeed he meant to say "I won't use any HTML entity as a PHP
> variable", didn't you Derick ?
Yes, I meant that.
>
> Those are well-known and not so many... Indeed, if your $myvar becomes
> an HTML entity, then you have to rewrite your code to escape all
> "&myvar" from it and Jon is right in saying that you should
> htmlentities($your_query)... (You also have to blame w3c ;-)
I think I'll write them a letter.
Derick Rethans