Re: $$vars and security

From: Date: Tue, 25 Nov 2003 09:58:36 +0000
Subject: Re: $$vars and security
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-170862@lists.php.net to get a copy of this message
great point about the array; to make the script more portable i will most definitely detect magic quotes. "Marek Kilimajer" <kilimajer@webglobe.sk> wrote in message news:3FC31FC5.6020702@webglobe.sk... > Phillip Jackson wrote: > > > > function escape(){ > > while (list($key, $value) = each($_POST)) { > > $value = trim(mysql_escape_string($value)); > > global $$key; > > $$key = $value; > > } > > } > > > > 1. The function does not detect if magic_quotes_gpc are on, post vars > would be double escaped then. > > 2. $value might be an array (<input name="var[]" ...>), the array would > be effectively destroyed.

« previous php.general (#170862) next »