note 36702 deleted from function.extract by aidan

From: Date: Thu, 09 Sep 2004 09:14:35 +0000
Subject: note 36702 deleted from function.extract by aidan
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-76292@lists.php.net to get a copy of this message
Note Submitter: mina86 at tlen dot pl ---- Re peppe1001 @ 01-Sep-2003 07:55: Note that extracting $_POST, $_GET, ... vars to global varible table is sooo insecure.. It's enought to send: Cookie: REMOTE_ADDR=127.0.0.1 header to make your script think that request was made from localhost.. It is strongly recommended that you use $_* arrays but if you realy want to have $_* vars extracted better use something like: <?php if (phpversion() >= 4.2) { extract($_POST, EXTR_PREFIX_ALL, 'VARS_'); extract($_GET, EXTR_PREFIX_ALL, 'VARS_'); extract($_SERVER, EXTR_PREFIX_ALL, 'SERVER_'); extract($_FILES, EXTR_PREFIX_ALL, 'FILES_'); extract($_ENV, EXTR_PREFIX_ALL, 'ENV_'); extract($_COOKIE, EXTR_PREFIX_ALL, 'COOKIE_'); extract($_SESSION, , EXTR_PREFIX_ALL, 'SESSION_'); } ?> However then I don't see any reason to do this..

« previous php.notes (#76292) next »