Re: allow_url_fopen should be INI_ALL
| From: | Etienne Kneuss | Date: | Thu, 30 Jun 2005 01:03:53 +0000 |
| Subject: | Re: allow_url_fopen should be INI_ALL | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-17025@lists.php.net to get a copy of this message | ||
Russell Nelson wrote:
>And you're trying to tell me that PHP's 'include' doesn't have a
>problem??
>
>
>
The problem is not located on include, the problem is more general :
"trusting user's data" and PHP already provides tools to make it safe,
like file_exists(), htmlentities(), etc...
--
Etienne Kneuss
http://www.colder.ch/
colder@php.net