note 32791 deleted from function.include by vincent
| From: | vincent@php.net | Date: | Mon, 08 Sep 2003 14:58:05 +0000 |
| Subject: | note 32791 deleted from function.include by vincent | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-55828@lists.php.net to get a copy of this message | ||
Note Submitter: lordwo_NOSPAM_@laposte_NOBOTS_.net
----
For users that absolutely want to include($_GET["something"]). As said above by many
peaple, it's a very bad idea because of the security issues it brings.
A simple way to correct this (even for novice users) is to implement a switch, referring to all your
scripts :
(That supposes that you already know the script names you will include...)
Exemple:
========
switch ($_GET["pagetoinclude"]) {
case "tomatoes":
include("tomatoes.php");
break;
case "apples":
include("apple.php");
break;
default:
include("error.php?msg=Bad-Parameter");
}
End of exemple
============
This way, you won't have any bad surprises with kiddies playing with arguments.
(Hope this helps)