Re: $$vars and security
| From: | Phillip Jackson | Date: | Tue, 25 Nov 2003 09:58:36 +0000 |
| Subject: | Re: $$vars and security | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-170862@lists.php.net to get a copy of this message | ||
great point about the array; to make the script more portable i will most
definitely detect magic quotes.
"Marek Kilimajer" <kilimajer@webglobe.sk> wrote in message
news:3FC31FC5.6020702@webglobe.sk...
> Phillip Jackson wrote:
> >
> > function escape(){
> > while (list($key, $value) = each($_POST)) {
> > $value = trim(mysql_escape_string($value));
> > global $$key;
> > $$key = $value;
> > }
> > }
> >
>
> 1. The function does not detect if magic_quotes_gpc are on, post vars
> would be double escaped then.
>
> 2. $value might be an array (<input name="var[]" ...>), the array would
> be effectively destroyed.