我需要過濾不可靠的$ _SERVER ['PHP_SELF']變量。這是一個好方法:
function filterPhpSelf($str)
{
$phpself = basename(__FILE__);
$str = substr($str, 0, strpos($str,$phpself)) . $phpself;
return $unsafeStr;
}
其中$ str是$ _SERVER ['PHP_SELF']?
我需要過濾不可靠的$ _SERVER ['PHP_SELF']變量。這是一個好方法:
function filterPhpSelf($str)
{
$phpself = basename(__FILE__);
$str = substr($str, 0, strpos($str,$phpself)) . $phpself;
return $unsafeStr;
}
其中$ str是$ _SERVER ['PHP_SELF']?
是的,這樣做。雖然你會想要改變:
return $unsafeStr;
到
return $str;
那你想篩選出什麼? – Gumbo 2009-05-05 14:02:28
什麼是不可靠的呢? – DisgruntledGoat 2009-05-05 16:10:54