note 31076 deleted from control-structures.foreach by sniper

From: Date: Wed, 08 Oct 2003 04:06:05 +0000
Subject: note 31076 deleted from control-structures.foreach by sniper
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-58004@lists.php.net to get a copy of this message
Note Submitter: noel.darlow2@virgin.net ---- SECURITY ISSUE I've often seen people use foreach to declare & process all the POST vars in one go with this: foreach ($_POST as $key => $value) { $$key = addslashes($value); } This is extremely unsafe. A forged form could have submitted any var with any value to your processor script. If they know / guess a previously declared var in the same scope as the foreach code, it would be overwritten (for example an $access_level var could be reset to 'admin'). The safe way to do it would be: foreach ($_POST as $key => $value) { ${'prefix_' . $key} = addslashes ($value); } .. or better still if the POST vars are stored in a db for later display in a browser (as they usually are): foreach ($_POST as $key => $value) { ${'prefix_' . $key} = htmlspecialchars(addslashes(trim($value))); } Of course, you have to be sure that your choice of string for 'prefix_' isn't part of a valid variable name...

« previous php.notes (#58004) next »