Re: is my form safe enough ?
| From: | Bas Jobsen | Date: | Fri, 23 Aug 2002 08:37:47 +0000 |
| Subject: | Re: is my form safe enough ? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-113734@lists.php.net to get a copy of this message | ||
I can place a form on a other location like:
<form action='http://mydomain.com/form.php'
method='POST'>
<input type='text' name='var' value='somejunkVal'>
<input type='submit' name='submit' value='fake'>
</form>
Op vrijdag 23 augustus 2002 09:43, schreef Roger Thomas:
> if the below snippet is called form.php,
> have I done enough to prevent something like:
> http://mydomain.com/form.php?var=somejunkVal
>
> nb: my register_globals = on
>
> <?
> if ($_POST["submit"]) {
> print "the value that you typed was:". $_POST["var"];
> /*
> write $_POST["var"] to db
> ...
> ...
> ...
> */
> }
> else {
> ?>
> <form action="<? echo $_SERVER["PHP_SELF"] ?>" method=post>
> <input type=text name=var>
> <br>
> <input type=submit name=submit value=submit>
> </form>
> <?
> }
> ?>
>
> --
> roger
>
>
> __________________________________________________
> Do You Yahoo!?
> Yahoo! Finance - Get real-time stock quotes
> http://finance.yahoo.com