note 30977 deleted from function.extract by sniper

From: Date: Sun, 13 Jul 2003 01:57:49 +0000
Subject: note 30977 deleted from function.extract by sniper
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-52001@lists.php.net to get a copy of this message
Note Submitter: noel.darlow2@virgin.net ---- IMPORTANT The post by.. destes (at) ix.netcom.com 13-May-2002 03:13 shows how to save time by extracting GET vars in one line BUT this is very unsafe, given that GET vars are vulnerable to query string tampering. A hacker could exploit this to over-write any variable in the same scope as the extract() line. extract($_POST, EXTR_PREFIX_ALL, "prefix"); ..would fix it (as long as you choose a "prefix" which doesn't re-create any existing var names). I've seen people using extract() in the same way for $_POST vars - same deal.

« previous php.notes (#52001) next »