Re: $$vars and security

From: Date: Tue, 25 Nov 2003 09:24:21 +0000
Subject: Re: $$vars and security
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-170861@lists.php.net to get a copy of this message
Phillip Jackson wrote:
function escape(){ while (list($key, $value) = each($_POST)) { $value = trim(mysql_escape_string($value)); global $$key; $$key = $value; } }
1. The function does not detect if magic_quotes_gpc are on, post vars would be double escaped then. 2. $value might be an array (<input name="var[]" ...>), the array would be effectively destroyed.

« previous php.general (#170861) next »