in reply to Automatic Parameters for CGIs
It also warns that this is a major security risk. If I happen to guess the name of one of your 'normal' variables and pass my own wicked bad parameters to your script, if you import into the main namespace, I can clobber any normal variable I can guess.
You cannot trust any of your normal variables after that happens. This is not something I recommend (and I seem to recall it's been responsible for a couple of security advisories for PHP, though I don't have a link offhand).
Use at your own risk.
Update: chipmunk says I should make it more clear that the security risk is importing variables into a package you're using. That's usually the main package, but any other package that doesn't expect it can be a victim.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Automatic Parameters for CGIs
by extremely (Priest) on Jan 19, 2001 at 06:08 UTC | |
by chipmunk (Parson) on Jan 19, 2001 at 21:33 UTC | |
by extremely (Priest) on Jan 20, 2001 at 12:08 UTC |