note 74649 added to function.extract

From: Date: Sat, 21 Apr 2007 19:25:56 +0000
Subject: note 74649 added to function.extract
Groups: php.notes 
Request: Send a blank email to php-notes+get-125755@lists.php.net to get a copy of this message
Following up on ktwombley at gmail dot com's post: Presumably one easy way of dealing with this security issue is to use the EXTR_IF_EXISTS flag and make sure a) your define acceptable input variables beforehand (i.e. as empty variables) b) Sanitise any user input to avoid unacceptable variable content. If you do these two things, then I'm not sure I see the difference between extract($_REQUEST,EXTR_IF_EXISTS); and assigning each of the variables by hand. I'm not talking here about the idea of storing the variables in a database, just the immediately necessary steps to allow you to use extract on REQUEST arrays with relative safety. ---- Server IP: 66.207.199.35 Probable Submitter: 209.107.111.138 ---- Manual Page -- http://www.php.net/manual/en/function.extract.php Edit -- https://master.php.net/note/edit/74649 Del: integrated -- https://master.php.net/note/delete/74649/integrated Del: useless -- https://master.php.net/note/delete/74649/useless Del: bad code -- https://master.php.net/note/delete/74649/bad+code Del: spam -- https://master.php.net/note/delete/74649/spam Del: non-english -- https://master.php.net/note/delete/74649/non-english Del: in docs -- https://master.php.net/note/delete/74649/in+docs Del: other reasons-- https://master.php.net/note/delete/74649 Reject -- https://master.php.net/note/reject/74649 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#125755) next »