note 32791 added to function.include
| From: | lordwo_NOSPAM_ at laposte_NOBOTS_ dot net | Date: | Fri, 06 Jun 2003 21:42:23 +0000 |
| Subject: | note 32791 added to function.include | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-49917@lists.php.net to get a copy of this message | ||
For users that absolutely want to include($_GET["something"]). As said above by many
peaple, it's a very bad idea because of the security issues it brings.
A simple way to correct this (even for novice users) is to implement a switch, referring to all your
scripts :
(That supposes that you already know the script names you will include...)
Exemple:
========
switch ($_GET["pagetoinclude"]) {
case "tomatoes":
include("tomatoes.php");
break;
case "apples":
include("apple.php");
break;
default:
include("error.php?msg=Bad-Parameter");
}
End of exemple
============
This way, you won't have any bad surprises with kiddies playing with arguments.
(Hope this helps)
----
Manual Page -- http://www.php.net/manual/en/function.include.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+32791
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+32791&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+32791&report=yes