Re: parse_str() patch
| From: | Stanislav Malyshev | Date: | Mon, 11 Sep 2000 20:07:40 +0000 |
| Subject: | Re: parse_str() patch | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32954@lists.php.net to get a copy of this message | ||
JB>> The version of the patch in 4.0.3-dev puts variables into the local
JB>> variable space even if the output array is passed into the function. If
JB>> you use parse_str() and give it the output array, you don't need the
JB>> variables to be set in the local space, and in some cases, this is even
JB>> undesirable.
JB>>
JB>> Imagine: You are using parse_str() to evaluate a string with untrusted
JB>> content. Someone could maliciously feed you a string that overwrites your
JB>> variables with their content.
Then you need to unset register_globals. Maybe I'll make some patch to do
it, but what your patch did was really wrong (name[] didn't work and there
were more problems with that).
--
Stanislav Malyshev stas@zend.com http://www.zend.com/
+972-3-6139665 ext.106