Re: parse_str() patch

From: Date: Mon, 11 Sep 2000 20:07:40 +0000
Subject: Re: parse_str() patch
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-32954@lists.php.net to get a copy of this message
JB>> The version of the patch in 4.0.3-dev puts variables into the local JB>> variable space even if the output array is passed into the function. If JB>> you use parse_str() and give it the output array, you don't need the JB>> variables to be set in the local space, and in some cases, this is even JB>> undesirable. JB>> JB>> Imagine: You are using parse_str() to evaluate a string with untrusted JB>> content. Someone could maliciously feed you a string that overwrites your JB>> variables with their content. Then you need to unset register_globals. Maybe I'll make some patch to do it, but what your patch did was really wrong (name[] didn't work and there were more problems with that). -- Stanislav Malyshev stas@zend.com http://www.zend.com/ +972-3-6139665 ext.106

« previous php.dev (#32954) next »