note 63643 deleted from function.header by bjori
| From: | bjori@php.net | Date: | Mon, 27 Mar 2006 09:40:51 +0000 |
| Subject: | note 63643 deleted from function.header by bjori | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-106703@lists.php.net to get a copy of this message | ||
Note Submitter: judas dot iscariote at gmail dot com
----
dmitry dot polushkin at gmail dot com function is vulnerable to header injection in versions older
that 4.4.2/5.1.2
If you want soemthing similar but working correctly an safe, use the redirect() method in class
HTTP.php ( part of PEAR ).
<?php
require_once 'HTTP.php';
HTTP::redirect($url,true,true);
?>
this ends the execution of the script(second param , no need for exit ), and sends a text response
for system not supporting redirect (third parameter),also it will create an absolute URl, from a
relative one,taking care of the details.