note 30977 deleted from function.extract by sniper
| From: | sniper@php.net | Date: | Sun, 13 Jul 2003 01:57:49 +0000 |
| Subject: | note 30977 deleted from function.extract by sniper | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-52001@lists.php.net to get a copy of this message | ||
Note Submitter: noel.darlow2@virgin.net
----
IMPORTANT
The post by..
destes (at) ix.netcom.com
13-May-2002 03:13
shows how to save time by extracting GET vars in one line BUT this is very unsafe, given that GET
vars are vulnerable to query string tampering.
A hacker could exploit this to over-write any variable in the same scope as the extract() line.
extract($_POST, EXTR_PREFIX_ALL, "prefix");
..would fix it (as long as you choose a "prefix" which doesn't re-create any existing
var names).
I've seen people using extract() in the same way for $_POST vars - same deal.