note 74649 added to function.extract
| From: | DanO | Date: | Sat, 21 Apr 2007 19:25:56 +0000 |
| Subject: | note 74649 added to function.extract | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-125755@lists.php.net to get a copy of this message | ||
Following up on ktwombley at gmail dot com's post:
Presumably one easy way of dealing with this security issue is to use the EXTR_IF_EXISTS flag and
make sure
a) your define acceptable input variables beforehand (i.e. as empty variables)
b) Sanitise any user input to avoid unacceptable variable content.
If you do these two things, then I'm not sure I see the difference between
extract($_REQUEST,EXTR_IF_EXISTS); and assigning each of the variables by hand.
I'm not talking here about the idea of storing the variables in a database, just the
immediately necessary steps to allow you to use extract on REQUEST arrays with relative safety.
----
Server IP: 66.207.199.35
Probable Submitter: 209.107.111.138
----
Manual Page -- http://www.php.net/manual/en/function.extract.php
Edit -- https://master.php.net/note/edit/74649
Del: integrated -- https://master.php.net/note/delete/74649/integrated
Del: useless -- https://master.php.net/note/delete/74649/useless
Del: bad code -- https://master.php.net/note/delete/74649/bad+code
Del: spam -- https://master.php.net/note/delete/74649/spam
Del: non-english -- https://master.php.net/note/delete/74649/non-english
Del: in docs -- https://master.php.net/note/delete/74649/in+docs
Del: other reasons-- https://master.php.net/note/delete/74649
Reject -- https://master.php.net/note/reject/74649
Search -- https://master.php.net/manage/user-notes.php