note 92190 added to function.checkdate
| From: | Anonymous at osu1 dot php dot net | Date: | Mon, 13 Jul 2009 19:06:48 +0000 |
| Subject: | note 92190 added to function.checkdate | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-158247@lists.php.net to get a copy of this message | ||
Beware that checkdate can not be used as validation to check if a date is correct.
The example below will return bool(true) which can result that the <script> part is inserted
into the database.
<?php
$date = "01-01-1980 <script>alert('test');</script>";
$aDate_parts = preg_split("/[\s-]+/", $date);
var_dump(
checkdate(
$aDate_parts[1], // Month
$aDate_parts[0], // Day
$aDate_parts[2] // Year
)
);
?>
----
Server IP: 83.137.20.135
Probable Submitter: 86.91.234.43
----
Manual Page -- http://www.php.net/manual/en/function.checkdate.php
Edit -- https://master.php.net/note/edit/92190
Del: integrated -- https://master.php.net/note/delete/92190/integrated
Del: useless -- https://master.php.net/note/delete/92190/useless
Del: bad code -- https://master.php.net/note/delete/92190/bad+code
Del: spam -- https://master.php.net/note/delete/92190/spam
Del: non-english -- https://master.php.net/note/delete/92190/non-english
Del: in docs -- https://master.php.net/note/delete/92190/in+docs
Del: other reasons-- https://master.php.net/note/delete/92190
Reject -- https://master.php.net/note/reject/92190
Search -- https://master.php.net/manage/user-notes.php