note 20460 added to features.remote-files

From: Date: Thu, 04 Apr 2002 12:21:19 +0000
Subject: note 20460 added to features.remote-files
Groups: php.notes 
Request: Send a blank email to php-notes+get-28601@lists.php.net to get a copy of this message
The easiest solution to this security risk is, in my oppinion, to add a host string in front of the url specified in the url adress. example: <html> <head><title>php.net</title></head> <body> <?php include("http://www.php.net/".$HTTP_GET_VARS["url"]); ?> </body> </html> yup =) It's impossible to include() an page from another server. Regards, Christer Frostmo Norway www.frostmo.com -- http://www.php.net/manual/en/features.remote-files.php http://master.php.net/manage/user-notes.php?action=edit+20460 http://master.php.net/manage/user-notes.php?action=delete+20460 http://master.php.net/manage/user-notes.php?action=reject+20460

« previous php.notes (#28601) next »