#23001 [Fbk->Csd]: Bug in documentation of SESSIONs
| From: | alindeman@php.net | Date: | Wed, 02 Apr 2003 12:39:17 +0000 |
| Subject: | #23001 [Fbk->Csd]: Bug in documentation of SESSIONs | ||
| References: | 1 | Groups: | php.doc |
| Request: | Send a blank email to phpdoc+get-969352443@lists.php.net to get a copy of this message | ||
ID: 23001
Updated by: alindeman@php.net
Reported By: sesser@php.net
-Status: Feedback
+Status: Closed
Bug Type: Documentation problem
Operating System: *
PHP Version: 5CVS-2003-04-01 (dev)
New Comment:
This bug has been fixed in CVS.
In case this was a PHP problem, snapshots of the sources are packaged
every three hours; this change will be in the next snapshot. You can
grab the snapshot at http://snaps.php.net/.
In case this was a documentation problem, the fix will show up soon at
http://www.php.net/manual/.
In case this was a PHP.net website problem, the change will show
up on the PHP.net site and on the mirror sites in short time.
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2003-04-02 03:35:34] sesser@php.net
Do whatever you like strip_tags(),urlencode(),html_entities()
just replace the simple echo SID stuff.
------------------------------------------------------------------------
[2003-04-01 17:14:32] alindeman@php.net
What do you suggest be done with it?
------------------------------------------------------------------------
[2003-04-01 05:52:04] sesser@php.net
Documentation suggest to output SID with a simple
echo -> vulnerable to Cross Site Scripting
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=23001&edit=1