note 20016 deleted from ref.filesystem by philip

From: Date: Sun, 13 Oct 2002 21:54:54 +0000
Subject: note 20016 deleted from ref.filesystem by philip
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-38033@lists.php.net to get a copy of this message
The guestbook above allows people to enter PHP code, and have it execute. This is, therefore, a massive security hole. A better way would be to replace the "include" with something like: echo nl2br( htmlentities( join( "", file( "gbook.txt" ) ) ) ); I confess to not having tried that, it's just a suggestion, and may not work. The main thing is that we read from the file and process the data for display, and never simply include it. This also stops people from putting HTML in, which isn't a security risk, just an irritant.

« previous php.notes (#38033) next »