cvs: phpweb / release_4_1_0.php

From: Date: Tue, 11 Dec 2001 20:13:03 +0000
Subject: cvs: phpweb / release_4_1_0.php
Groups: php.mirrors 
Request: Send a blank email to php-mirrors+get-7790@lists.php.net to get a copy of this message
jimw Tue Dec 11 15:13:03 2001 EDT Modified files: /phpweb release_4_1_0.php Log: whoops, add <?php back to code examples Index: phpweb/release_4_1_0.php diff -u phpweb/release_4_1_0.php:1.8 phpweb/release_4_1_0.php:1.9 --- phpweb/release_4_1_0.php:1.8 Tue Dec 11 15:10:41 2001 +++ phpweb/release_4_1_0.php Tue Dec 11 15:13:03 2001 @@ -109,12 +109,12 @@ a part of the global namespace, automatically) are very often exploitable to various degrees. For example, the piece of code:</p> -<?php highlight_string(' +<?php highlight_string('<?php if (authenticate_user()) { $authenticated = true; } ... -');?> +?>');?> <p>May be exploitable, as remote users can simply pass on 'authenticated' as a form variable, and then even if authenticate_user() returns false, @@ -151,11 +151,12 @@ scope. This means that you can access them anywhere, without having to 'global' them first. For example:</p> -<?php highlight_string(' +<?php highlight_string('<?php function example1() { print $_GET["name"]; // works, \'global $_GET;\' is not necessary! -}');?> +} +?>');?> <p>would work fine! We hope that this fact would ease the pain in migrating old code to new code a bit, and we're confident it's going to make writing

« previous php.mirrors (#7790) next »