note 23991 added to security.registerglobals
| From: | joe at cfcl dot com | Date: | Sat, 03 Aug 2002 01:24:28 +0000 |
| Subject: | note 23991 added to security.registerglobals | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-34168@lists.php.net to get a copy of this message | ||
Hrm, it seems to me a safer thing to do would be to functionize the above -and provide an argument-.
function import($var)
{
if(isset($HTTP_GET_VARS[$var]))
{
$$var = $HTTP_GET_VARS[$var];
print "$var in get";
} else if(isset($HTTP_POST_VARS[$var]))
{
$$var = $HTTP_POST_VARS[$var];
print "$var in post";
}
}
I'm 99% sure this will work, once I add $GLOBALS[] in the appropriate places (I'm a bit
new at this here PHP stuff ;)
This way, you can explicitly import only the variables you need, when you need them. Of course
there's the usual caveats about content checking etc, but I think this will go a long way to
help.
--
http://www.php.net/manual/en/security.registerglobals.php
http://master.php.net/manage/user-notes.php?action=edit+23991
http://master.php.net/manage/user-notes.php?action=delete+23991
http://master.php.net/manage/user-notes.php?action=reject+23991