note 31076 deleted from control-structures.foreach by sniper
| From: | sniper@php.net | Date: | Wed, 08 Oct 2003 04:06:05 +0000 |
| Subject: | note 31076 deleted from control-structures.foreach by sniper | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-58004@lists.php.net to get a copy of this message | ||
Note Submitter: noel.darlow2@virgin.net
----
SECURITY ISSUE
I've often seen people use foreach to declare & process all the POST vars in one go with
this:
foreach ($_POST as $key => $value) {
$$key = addslashes($value);
}
This is extremely unsafe. A forged form could have submitted any var with any value to your
processor script. If they know / guess a previously declared var in the same scope as the foreach
code, it would be overwritten (for example an $access_level var could be reset to
'admin').
The safe way to do it would be:
foreach ($_POST as $key => $value) {
${'prefix_' . $key} = addslashes ($value);
}
.. or better still if the POST vars are stored in a db for later display in a browser (as they
usually are):
foreach ($_POST as $key => $value) {
${'prefix_' . $key} = htmlspecialchars(addslashes(trim($value)));
}
Of course, you have to be sure that your choice of string for 'prefix_' isn't part of
a valid variable name...