note 25346 added to function.highlight-file
| From: | serged at chez dot com | Date: | Fri, 20 Sep 2002 11:11:07 +0000 |
| Subject: | note 25346 added to function.highlight-file | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-37027@lists.php.net to get a copy of this message | ||
Another security hole with this function:
If you want to enable anybody to see your sources, and you create a page as "viewsrc.php"
wich take the name of the page in parameter, anybody can see your passwords (of sql table for
example) in the page!
Use rather highlight_string() with a filtered version of the file.
--
http://www.php.net/manual/en/function.highlight-file.php
http://master.php.net/manage/user-notes.php?action=edit+25346
http://master.php.net/manage/user-notes.php?action=delete+25346
http://master.php.net/manage/user-notes.php?action=reject+25346