Re: The man-that-makes-me-sick returns (Was: PHP File Upload Security Hole - Still No Fix?)

From: Date: Wed, 06 Sep 2000 16:40:49 +0000
Subject: Re: The man-that-makes-me-sick returns (Was: PHP File Upload Security Hole - Still No Fix?)
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-32400@lists.php.net to get a copy of this message
> > Those are well-known and not so many... Indeed, if your $myvar becomes > > an HTML entity, then you have to rewrite your code to escape all > > "&myvar" from it and Jon is right in saying that you should > > htmlentities($your_query)... (You also have to blame w3c ;-) > > I think I'll write them a letter. It actually isn't their fault. And this is by no means a new problem. The W3C has urged people for years to use ';' as the separator in URLs. You can make PHP understand ; as the separator by setting the arg_separator .ini directive. Unfortunately browsers don't send semi-colon separated data, but if all you need is to pass data around in the URL by yourself and you aren't worried about forms, you can safely change the arg_separator. The spec reference for this is: http://www.w3.org/TR/html4/appendix/notes.html#h-B.2.2 -Rasmus

« previous php.dev (#32400) next »