RE: [PHP] form security problem
| From: | Boget, Chris | Date: | Wed, 11 Oct 2000 18:19:42 +0000 |
| Subject: | RE: [PHP] form security problem | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-19656@lists.php.net to get a copy of this message | ||
> Someone will probably come up with a better idea, but here goes.
> Since HTTP_REFERRER probably won't suffice (eg, they can just add the
> ?test=0 to the end of the URL),
Actually, as far as I understand, POST variables have precedence
over GET variables of the same name. So even if they did d0
"?test=0"
it wouldn't matter as the POST variable would be used instead.
Chris