note 72664 deleted from function.htmlentities by nlopess
| From: | nlopess@php.net | Date: | Tue, 30 Jan 2007 15:20:45 +0000 |
| Subject: | note 72664 deleted from function.htmlentities by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-122357@lists.php.net to get a copy of this message | ||
Note Submitter: wildcats1369
----
This procedure will change POST and GET variables how deep they might be to prevent Code Insertion.
I hope it becomes useful.
<?
if(isset($_POST))
{
$_POST=strip_array($_POST);
}
if(isset($_GET))
{
$_GET=strip_array($_GET);
}
function strip_array($array) //recursively
{
foreach($array as $key=>$value)
{
if(is_array($value))
{
$ret[$key]=strip_array($value);
}else
{
$ret[$key]=addslashes(htmlspecialchars($value,ENT_QUOTES));
}
}
return $ret;
}
?>