Re: parse_str() patch
| From: | John Bafford | Date: | Mon, 11 Sep 2000 16:26:31 +0000 |
| Subject: | Re: parse_str() patch | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32934@lists.php.net to get a copy of this message | ||
The version of the patch in 4.0.3-dev puts variables into the local
variable space even if the output array is passed into the function. If
you use parse_str() and give it the output array, you don't need the
variables to be set in the local space, and in some cases, this is even
undesirable.
Imagine: You are using parse_str() to evaluate a string with untrusted
content. Someone could maliciously feed you a string that overwrites your
variables with their content.
Can you fix this? Otherwise, this version of parse_str() is useless to me.
Thanks,
-John
On Mon, 11 Sep 2000, Stanislav Malyshev wrote:
> JB>> Attached is a patch against PHP 4.0.2 to allow parse_str() to allow an
> JB>> optional second argument to parse_str() that receives the contents of the
> JB>> string, rather than dumping the output into the currentlocal variable
> JB>> space.
>
> OK, I have integrated this patch - it shouldn't break anything, please
> check if it works as expected (I made some corrections to it, but it
> should be OK).
>
> --
> Stanislav Malyshev stas@zend.com http://www.zend.com/
>
> +972-3-6139665 ext.106
>
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>
--
John Bafford
dshadow@zort.net
http://www.dshadow.com/