note 32810 added to function.get-defined-vars
| From: | biyectivo at hotmail dot com | Date: | Sat, 07 Jun 2003 21:16:35 +0000 |
| Subject: | note 32810 added to function.get-defined-vars | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-49952@lists.php.net to get a copy of this message | ||
Thankfully, get_defined_vars() does NOT return variables which are assigned during an include()
call. This would be a big security hole. For example:
//---------------------------------------------------------
include("foo.php");
$var1 = "Hi";
$vars = get_defined_vars();
$ks = array_keys($vars);
for ($i=0;$i<sizeof($ks);$i++)
{
echo $ks[$i]." --> ".$vars[$ks[$i]]."< br >";
}
//---------------------------------------------------------
will return all server variables, then
var1 --> Hi
but will NOT return
pwd --> MyPassword
even if inside foo.php there is a line stating
$pwd = "MyPassword";
----
Manual Page -- http://www.php.net/manual/en/function.get-defined-vars.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+32810
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+32810&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+32810&report=yes