Posted by R. Rajesh Jeba Anbiah on 10/24/65 11:55
Robert wrote:
> The correct way to get the php file is:
>
> $_SERVER['PHP_SELF'] -- No security vulns. as per my knowledge.
<snip>
Read the thread above. The security issue was a big noise sometimes
ago; until that time, I was using $_SERVER['PHP_SELF']; but now using
$_SERVER['SCRIPT_NAME']
--
<?php echo 'Just another PHP saint'; ?>
Email: rrjanbiah-at-Y!com Blog: http://rajeshanbiah.blogspot.com/
Navigation:
[Reply to this message]
|