note 92190 added to function.checkdate

From: Date: Mon, 13 Jul 2009 19:06:48 +0000
Subject: note 92190 added to function.checkdate
Groups: php.notes 
Request: Send a blank email to php-notes+get-158247@lists.php.net to get a copy of this message
Beware that checkdate can not be used as validation to check if a date is correct. The example below will return bool(true) which can result that the <script> part is inserted into the database. <?php $date = "01-01-1980 <script>alert('test');</script>"; $aDate_parts = preg_split("/[\s-]+/", $date); var_dump( checkdate( $aDate_parts[1], // Month $aDate_parts[0], // Day $aDate_parts[2] // Year ) ); ?> ---- Server IP: 83.137.20.135 Probable Submitter: 86.91.234.43 ---- Manual Page -- http://www.php.net/manual/en/function.checkdate.php Edit -- https://master.php.net/note/edit/92190 Del: integrated -- https://master.php.net/note/delete/92190/integrated Del: useless -- https://master.php.net/note/delete/92190/useless Del: bad code -- https://master.php.net/note/delete/92190/bad+code Del: spam -- https://master.php.net/note/delete/92190/spam Del: non-english -- https://master.php.net/note/delete/92190/non-english Del: in docs -- https://master.php.net/note/delete/92190/in+docs Del: other reasons-- https://master.php.net/note/delete/92190 Reject -- https://master.php.net/note/reject/92190 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#158247) next »