RE: [PHP] Security alert and question: semicolon taint

From: Date: Mon, 04 Sep 2000 05:26:14 +0000
Subject: RE: [PHP] Security alert and question: semicolon taint
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-15057@lists.php.net to get a copy of this message
> God damn it! Why can't this mailing list default to > php-general@lists.php.net for replies? We have been through this before. It is against all common sense to do so. Mail header mangling is bad. If I set a reply-to on an email I send to a mailing list, I expect it to be honoured, and I don't expect anybody to arbitrarily add a reply-to header to my email under any circumstances. > At 22:03 9/3/2000 -0700, you wrote: > > > Yes, but that's not that big of a worry. Since it would only affect users > > > with malicious intent. > > > >How so? You can't pass a database "0" when it is expecting 0 > > Actually, you can. I just tried it and got away with it. Might depend on the database, I suppose. I know for sure MySQL doesn't like it. -Rasmus

« previous php.general (#15057) next »