note 23991 modified in security.registerglobals by dams

From: Date: Sat, 03 Aug 2002 18:20:16 +0000
Subject: note 23991 modified in security.registerglobals by dams
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-34234@lists.php.net to get a copy of this message
Hrm, it seems to me a safer thing to do would be to functionize the above -and provide an argument-. function import($var) { if(isset($HTTP_GET_VARS[$var])) { $$var = $HTTP_GET_VARS[$var]; } else if(isset($HTTP_POST_VARS[$var])) { $$var = $HTTP_POST_VARS[$var]; } } I'm 99% sure this will work, once I add $GLOBALS[] in the appropriate places (I'm a bit new at this here PHP stuff ;) This way, you can explicitly import only the variables you need, when you need them. Of course there's the usual caveats about content checking etc, but I think this will go a long way to help. --was-- Hrm, it seems to me a safer thing to do would be to functionize the above -and provide an argument-. function import($var) { if(isset($HTTP_GET_VARS[$var])) { $$var = $HTTP_GET_VARS[$var]; print "$var in get"; } else if(isset($HTTP_POST_VARS[$var])) { $$var = $HTTP_POST_VARS[$var]; print "$var in post"; } } I'm 99% sure this will work, once I add $GLOBALS[] in the appropriate places (I'm a bit new at this here PHP stuff ;) This way, you can explicitly import only the variables you need, when you need them. Of course there's the usual caveats about content checking etc, but I think this will go a long way to help. http://www.php.net/manual/en/security.registerglobals.php

« previous php.notes (#34234) next »