Re: $$vars and security
| From: | Marek Kilimajer | Date: | Tue, 25 Nov 2003 09:24:21 +0000 |
| Subject: | Re: $$vars and security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-170861@lists.php.net to get a copy of this message | ||
Phillip Jackson wrote:
function escape(){ while (list($key, $value) = each($_POST)) { $value = trim(mysql_escape_string($value)); global $$key; $$key = $value; } }1. The function does not detect if magic_quotes_gpc are on, post vars would be double escaped then. 2. $value might be an array (<input name="var[]" ...>), the array would be effectively destroyed.