note 25346 deleted from function.highlight-file by didou
| From: | didou@php.net | Date: | Mon, 04 Aug 2003 22:07:33 +0000 |
| Subject: | note 25346 deleted from function.highlight-file by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-53358@lists.php.net to get a copy of this message | ||
Note Submitter: serged@chez.com
----
Another security hole with this function:
If you want to enable anybody to see your sources, and you create a page as "viewsrc.php"
wich take the name of the page in parameter, anybody can see your passwords (of sql table for
example) in the page!
Use rather highlight_string() with a filtered version of the file.