note 36702 added to function.extract

From: Date: Sun, 19 Oct 2003 12:06:18 +0000
Subject: note 36702 added to function.extract
Groups: php.notes 
Request: Send a blank email to php-notes+get-58883@lists.php.net to get a copy of this message
Re peppe1001 @ 01-Sep-2003 07:55: Note that extracting $_POST, $_GET, ... vars to global varible table is sooo insecure.. It's enought to send: Cookie: REMOTE_ADDR=127.0.0.1 header to make your script think that request was made from localhost.. It is strongly recommended that you use $_* arrays but if you realy want to have $_* vars extracted better use something like: <?php if (phpversion() >= 4.2) { extract($_POST, EXTR_PREFIX_ALL, 'VARS_'); extract($_GET, EXTR_PREFIX_ALL, 'VARS_'); extract($_SERVER, EXTR_PREFIX_ALL, 'SERVER_'); extract($_FILES, EXTR_PREFIX_ALL, 'FILES_'); extract($_ENV, EXTR_PREFIX_ALL, 'ENV_'); extract($_COOKIE, EXTR_PREFIX_ALL, 'COOKIE_'); extract($_SESSION, , EXTR_PREFIX_ALL, 'SESSION_'); } ?> However then I don't see any reason to do this.. ---- Manual Page -- http://www.php.net/manual/en/function.extract.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+36702 Delete -- http://master.php.net/manage/user-notes.php?action=delete+36702&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+36702&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#58883) next »