note 30977 added to function.extract
| From: | noel dot darlow2 at virgin dot net | Date: | Sat, 05 Apr 2003 00:49:41 +0000 |
| Subject: | note 30977 added to function.extract | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-46244@lists.php.net to get a copy of this message | ||
IMPORTANT
The post by..
destes (at) ix.netcom.com
13-May-2002 03:13
shows how to save time by extracting GET vars in one line BUT this is very unsafe, given that GET
vars are vulnerable to query string tampering.
A hacker could exploit this to over-write any variable in the same scope as the extract() line.
extract($_POST, EXTR_PREFIX_ALL, "prefix");
..would fix it (as long as you choose a "prefix" which doesn't re-create any existing
var names).
I've seen people using extract() in the same way for $_POST vars - same deal.
--
http://www.php.net/manual/en/function.extract.php
http://master.php.net/manage/user-notes.php?action=edit+30977
http://master.php.net/manage/user-notes.php?action=delete+30977
http://master.php.net/manage/user-notes.php?action=reject+30977