Re: php v4.1.0 and new input security: easy backwards compat fix

From: Date: Tue, 18 Dec 2001 00:10:34 +0000
Subject: Re: php v4.1.0 and new input security: easy backwards compat fix
References: 1  Groups: php.mirrors 
Request: Send a blank email to php-mirrors+get-7894@lists.php.net to get a copy of this message
On December 17, 2001 03:06 pm, Tim Bolin wrote: > rather than people converting every variable that was set by the old > get or post methods, they can just add this code fragment to the top > of their files or to a header include that runs before anything > else... > > <? > extract($_REQUEST); > ?> > > this should make it possible to use the new more secure > register_globals=off without having to make extensive edits to the > software... > > just a little tip that might make some people's life easier... But if they do that then they are back in a situation where data provided via GPC can overwrite data set in the GLOBAL environment. extract() can be set to not overwrite existing data, however, this means dealing with data that has a prefix, which is no less effort than working with the $_GET, etc vars. :) -- Zak Greant PHP Quality Assurance Team http://qa.php.net/ "We must be the change we wish to see." - M. K. Ghandi

« previous php.mirrors (#7894) next »