Re[2]: [PHP] opendir security hole
| From: | Stuart Dallas | Date: | Mon, 03 Jun 2002 19:41:37 +0000 |
| Subject: | Re[2]: [PHP] opendir security hole | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-100458@lists.php.net to get a copy of this message | ||
On Monday, June 3, 2002 at 3:37:48 PM, you wrote:
> $dir = preg_replace('/\.\.\/?/', '', $dir);
Surely a regular expression is overkill for this? It would be more efficient to
use str_replace()...
$dir = str_replace('..', '', $dir);
--
Stuart