Re: Re: Did anyone have success with the require() function??
| From: | Scott Fletcher | Date: | Tue, 14 Oct 2003 14:22:49 +0000 |
| Subject: | Re: Re: Did anyone have success with the require() function?? | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-166068@lists.php.net to get a copy of this message | ||
Thanks...
"Tom Rogers" <trogers@kwikin.com> wrote in message
news:3208294890.20031011120738@kwikin.com...
> Hi,
>
> Saturday, October 11, 2003, 3:33:05 AM, you wrote:
> CZ> On Fri, 10 Oct 2003 13:09:16 -0400, Scott Fletcher <scott@abcoa.com>
wrote:
>
> >> Hi Fellas!
> >>
> >> Did anyone have success with making the required function work if using
> >> this sample code. It didn't work for me.
> >>
> >> --snip--
> >> require("$_REQUEST['PDF_LIB_PATH']");
> >> --snip--
>
> CZ> When you access an array inside of a string you half to tell php that
it
> CZ> is a variable by enclosing it with curly brackets:
>
> CZ> require("{$_REQUEST['PDF_LIB_PATH']}");
>
>
> CZ> Now the question is, what happens if I access your site like so:
>
> CZ>
> CZ> http://yoursite.com/yourfile.php?PDF_LIB_PATH=%2fetc%2fpasswd
>
>
> CZ> Always verify your data that is passed in by the user, you might
> CZ> want to read:
>
> CZ> http://php.net/manual/en/security.filesystem.php
>
> CZ> HTH,
>
> CZ> Curt
> CZ> --
>
>
> Or drop the quotes they are not needed if there are only variables
involved
>
> --
> regards,
> Tom