Re: allow_url_fopen should be INI_ALL

From: Date: Thu, 30 Jun 2005 01:03:53 +0000
Subject: Re: allow_url_fopen should be INI_ALL
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-17025@lists.php.net to get a copy of this message
Russell Nelson wrote: >And you're trying to tell me that PHP's 'include' doesn't have a >problem?? > > > The problem is not located on include, the problem is more general : "trusting user's data" and PHP already provides tools to make it safe, like file_exists(), htmlentities(), etc... -- Etienne Kneuss http://www.colder.ch/ colder@php.net

« previous php.internals (#17025) next »