$$vars and security

From: Date: Tue, 25 Nov 2003 05:57:11 +0000
Subject: $$vars and security
Groups: php.general 
Request: Send a blank email to php-general+get-170850@lists.php.net to get a copy of this message
i have developed my own "register globals" function that mimics the action of register globals, but only for $_POST... i do this to ensure that all incoming communication is escaped for use in scripts to account for, and to avoid, SQL injection. below is the code... any suggestions would be welcome to make this a more secure function for use to massage data going to MySQL: ==================================== function escape(){ while (list($key, $value) = each($_POST)) { $value = trim(mysql_escape_string($value)); global $$key; $$key = $value; } }

« previous php.general (#170850) next »