Re: The man-that-makes-me-sick returns (Was: PHP File Upload Security Hole - Still No Fix?)
| From: | Rasmus Lerdorf | Date: | Wed, 06 Sep 2000 16:40:49 +0000 |
| Subject: | Re: The man-that-makes-me-sick returns (Was: PHP File Upload Security Hole - Still No Fix?) | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32400@lists.php.net to get a copy of this message | ||
> > Those are well-known and not so many... Indeed, if your $myvar becomes
> > an HTML entity, then you have to rewrite your code to escape all
> > "&myvar" from it and Jon is right in saying that you should
> > htmlentities($your_query)... (You also have to blame w3c ;-)
>
> I think I'll write them a letter.
It actually isn't their fault. And this is by no means a new problem.
The W3C has urged people for years to use ';' as the separator in URLs.
You can make PHP understand ; as the separator by setting the
arg_separator .ini directive. Unfortunately browsers don't send
semi-colon separated data, but if all you need is to pass data around in
the URL by yourself and you aren't worried about forms, you can safely
change the arg_separator.
The spec reference for this is:
http://www.w3.org/TR/html4/appendix/notes.html#h-B.2.2
-Rasmus