note 30977 added to function.extract

From: Date: Sat, 05 Apr 2003 00:49:41 +0000
Subject: note 30977 added to function.extract
Groups: php.notes 
Request: Send a blank email to php-notes+get-46244@lists.php.net to get a copy of this message
IMPORTANT The post by.. destes (at) ix.netcom.com 13-May-2002 03:13 shows how to save time by extracting GET vars in one line BUT this is very unsafe, given that GET vars are vulnerable to query string tampering. A hacker could exploit this to over-write any variable in the same scope as the extract() line. extract($_POST, EXTR_PREFIX_ALL, "prefix"); ..would fix it (as long as you choose a "prefix" which doesn't re-create any existing var names). I've seen people using extract() in the same way for $_POST vars - same deal. -- http://www.php.net/manual/en/function.extract.php http://master.php.net/manage/user-notes.php?action=edit+30977 http://master.php.net/manage/user-notes.php?action=delete+30977 http://master.php.net/manage/user-notes.php?action=reject+30977

« previous php.notes (#46244) next »