note 20016 added to ref.filesystem
| From: | dave at cridland dot net | Date: | Tue, 19 Mar 2002 14:23:21 +0000 |
| Subject: | note 20016 added to ref.filesystem | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-27951@lists.php.net to get a copy of this message | ||
The guestbook above allows people to enter PHP code, and have it execute.
This is, therefore, a massive security hole.
A better way would be to replace the "include" with something like:
echo nl2br( htmlentities( join( "", file( "gbook.txt" ) ) ) );
I confess to not having tried that, it's just a suggestion, and may not work.
The main thing is that we read from the file and process the data for display, and never simply
include it.
This also stops people from putting HTML in, which isn't a security risk, just an irritant.
--
http://www.php.net/manual/en/ref.filesystem.php
http://master.php.net/manage/user-notes.php?action=edit+20016
http://master.php.net/manage/user-notes.php?action=delete+20016
http://master.php.net/manage/user-notes.php?action=reject+20016