$$vars and security
| From: | Phillip Jackson | Date: | Tue, 25 Nov 2003 05:57:11 +0000 |
| Subject: | $$vars and security | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-170850@lists.php.net to get a copy of this message | ||
i have developed my own "register globals" function that mimics the action
of register globals, but only for $_POST... i do this to ensure that all
incoming communication is escaped for use in scripts to account for, and to
avoid, SQL injection. below is the code... any suggestions would be welcome
to make this a more secure function for use to massage data going to MySQL:
====================================
function escape(){
while (list($key, $value) = each($_POST)) {
$value = trim(mysql_escape_string($value));
global $$key;
$$key = $value;
}
}