cvs: phpweb / release_4_1_0.php
| From: | jim winstead | Date: | Tue, 11 Dec 2001 20:13:03 +0000 |
| Subject: | cvs: phpweb / release_4_1_0.php | ||
| Groups: | php.mirrors | ||
| Request: | Send a blank email to php-mirrors+get-7790@lists.php.net to get a copy of this message | ||
jimw Tue Dec 11 15:13:03 2001 EDT
Modified files:
/phpweb release_4_1_0.php
Log:
whoops, add <?php back to code examples
Index: phpweb/release_4_1_0.php
diff -u phpweb/release_4_1_0.php:1.8 phpweb/release_4_1_0.php:1.9
--- phpweb/release_4_1_0.php:1.8 Tue Dec 11 15:10:41 2001
+++ phpweb/release_4_1_0.php Tue Dec 11 15:13:03 2001
@@ -109,12 +109,12 @@
a part of the global namespace, automatically) are very often
exploitable to various degrees. For example, the piece of code:</p>
-<?php highlight_string('
+<?php highlight_string('<?php
if (authenticate_user()) {
$authenticated = true;
}
...
-');?>
+?>');?>
<p>May be exploitable, as remote users can simply pass on 'authenticated'
as a form variable, and then even if authenticate_user() returns false,
@@ -151,11 +151,12 @@
scope. This means that you can access them anywhere, without having to
'global' them first. For example:</p>
-<?php highlight_string('
+<?php highlight_string('<?php
function example1()
{
print $_GET["name"]; // works, \'global $_GET;\' is not necessary!
-}');?>
+}
+?>');?>
<p>would work fine! We hope that this fact would ease the pain in migrating
old code to new code a bit, and we're confident it's going to make writing