note 23991 modified in security.registerglobals by dams
| From: | dams@php.net | Date: | Sat, 03 Aug 2002 18:20:16 +0000 |
| Subject: | note 23991 modified in security.registerglobals by dams | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-34234@lists.php.net to get a copy of this message | ||
Hrm, it seems to me a safer thing to do would be to functionize the above -and provide an argument-.
function import($var)
{
if(isset($HTTP_GET_VARS[$var]))
{
$$var = $HTTP_GET_VARS[$var];
} else if(isset($HTTP_POST_VARS[$var]))
{
$$var = $HTTP_POST_VARS[$var];
}
}
I'm 99% sure this will work, once I add $GLOBALS[] in the appropriate places (I'm a bit
new at this here PHP stuff ;)
This way, you can explicitly import only the variables you need, when you need them. Of course
there's the usual caveats about content checking etc, but I think this will go a long way to
help.
--was--
Hrm, it seems to me a safer thing to do would be to functionize the above -and provide an argument-.
function import($var)
{
if(isset($HTTP_GET_VARS[$var]))
{
$$var = $HTTP_GET_VARS[$var];
print "$var in get";
} else if(isset($HTTP_POST_VARS[$var]))
{
$$var = $HTTP_POST_VARS[$var];
print "$var in post";
}
}
I'm 99% sure this will work, once I add $GLOBALS[] in the appropriate places (I'm a bit
new at this here PHP stuff ;)
This way, you can explicitly import only the variables you need, when you need them. Of course
there's the usual caveats about content checking etc, but I think this will go a long way to
help.
http://www.php.net/manual/en/security.registerglobals.php