note 54600 added to function.import-request-variables
| From: | jason at osu1 dot php dot net | Date: | Fri, 08 Jul 2005 19:35:58 +0000 |
| Subject: | note 54600 added to function.import-request-variables | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-91698@lists.php.net to get a copy of this message | ||
reply to ceo AT l-i-e DOT com:
I don't think it's a risk, as all of your request variables will be tagged with the
prefix. As long as you don't prefix any of your internal variables with the same, you should be
fine.
If someone tries to access an uninitiated security-related variable like $admin_level through
request data, it will get imported as $RV_admin_level.
----
Manual Page -- http://www.php.net/manual/en/function.import-request-variables.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+54600
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+54600&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+54600&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+54600&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+54600&report=yes&reason=useless
Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+54600&report=yes&reason=non-english
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+54600&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+54600&report=yes
Search -- http://master.php.net/manage/user-notes.php