note 36702 added to function.extract
| From: | mina86 at tlen dot pl | Date: | Sun, 19 Oct 2003 12:06:18 +0000 |
| Subject: | note 36702 added to function.extract | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-58883@lists.php.net to get a copy of this message | ||
Re peppe1001 @ 01-Sep-2003 07:55:
Note that extracting $_POST, $_GET, ... vars to global varible table is sooo insecure.. It's
enought to send:
Cookie: REMOTE_ADDR=127.0.0.1
header to make your script think that request was made from localhost.. It is strongly recommended
that you use $_* arrays but if you realy want to have $_* vars extracted better use something like:
<?php
if (phpversion() >= 4.2) {
extract($_POST, EXTR_PREFIX_ALL, 'VARS_');
extract($_GET, EXTR_PREFIX_ALL, 'VARS_');
extract($_SERVER, EXTR_PREFIX_ALL, 'SERVER_');
extract($_FILES, EXTR_PREFIX_ALL, 'FILES_');
extract($_ENV, EXTR_PREFIX_ALL, 'ENV_');
extract($_COOKIE, EXTR_PREFIX_ALL, 'COOKIE_');
extract($_SESSION, , EXTR_PREFIX_ALL, 'SESSION_');
}
?>
However then I don't see any reason to do this..
----
Manual Page -- http://www.php.net/manual/en/function.extract.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+36702
Delete -- http://master.php.net/manage/user-notes.php?action=delete+36702&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+36702&report=yes
Search -- http://master.php.net/manage/user-notes.php