Re: extract($_POST)

From: Date: Tue, 22 Oct 2002 22:44:07 +0000
Subject: Re: extract($_POST)
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-120995@lists.php.net to get a copy of this message
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 That is still as dangerous as 'register_global=on' security wise. ~Paul On Tuesday 22 October 2002 02:30 pm, Rick Emery wrote: > Yes, it's safe. To test it yourself, construct a form and name a variable > MYVAR. Display and submit the form so that it passes to a .PHP script. Do > extract($_POST) or extract($HTTP_POST_VARS), and print out the value of > MYVAR > ----- Original Message ----- > From: <ed@home.homes2see.com> > To: <php-general@lists.php.net> > Sent: Tuesday, October 22, 2002 1:25 PM > Subject: [PHP] extract($_POST) > > > > Is it safe to assume then that it would be just as safe to use this > command on existing scripts and call this function at the top of every > page you would need to extract post variables from rather as > opposed to rewriting the scripts to use the $_POST['var'] declaration? > > Ed > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php > > - -- ~Paul Nicholson Design Specialist @ WebPower Design "The web....the way you want it!" paul@webpowerdesign.net "It said uses Windows 98 or better, so I loaded Linux!" Registered Linux User #183202 using Register Linux System # 81891 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQE9tdS8DyXNIUN3+UQRAmjPAJ9SH6VKegJk6KzTksne55564tAq5QCfdl+g eBmDkEXRXQNFlLubFMnesZE= =C2P8 -----END PGP SIGNATURE-----

« previous php.general (#120995) next »