Re: Quotes in GET variables

From: Date: Mon, 21 May 2001 12:15:45 +0000
Subject: Re: Quotes in GET variables
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-53703@lists.php.net to get a copy of this message
> It's a feature of PHP that it automatically escapes data submitted in > PUT/GET/etc. It didn't seem to be happening with POST which is why I thought it odd, but that probably means I didn't test properly :-) > It's nice in that it adds to how secure PHP code is, but it can be a hassle. Out of curiousity, what are the security implications? Presumably a failure to validate input properly leading to unintended actions, but I can't think of any examples to help me decide whether to turn this off. Thanks for the quick response. -- Mark Rogers

« previous php.general (#53703) next »