You are here: Re: _GET['name'] truncates « PHP Programming Language « IT news, forums, messages
Re: _GET['name'] truncates

Posted by Kim Andrι Akerψ on 02/05/07 23:54

Jerry Stuckle wrote:

> Rik wrote:
> >Ramon <info@kwekerijschiffelers.nl> wrote:
> >
> > > The length of the string is +/= 1200 characters. The maximum for
> > > IE is 2048, and for other browsers even longer...
> > >
> >
> > Hmmz, you're right. I've tested it, and here it works perfectly.
> > rawurlencoded yields about 1270 characters, and I can get them back
> > nicely without any trouble, the full string.
> >
> > Seems a configuration issue of either PHP, browser of webserver to
> > me, but I'm not going to find out: it still seems very silly to me
> > to try this in a GET. --Rik Wasmus
>
> Yep, in addition, it's very insecure. I could just put in my browser
> windows
>
> http://www.example.com?sql=delete%20from%20orders

Or even worse (just to prove a point to the OP):
http://www.example.com?sql=drop%20table%20orders

> You shouldn't even attempt to put a sql statement in the $_GET or
> $_POST string. Rather, put only the values you need for the query.
>
> Or save the query in the $_SESSION.

--
Kim AndrΓ© AkerΓΈ
- kimandre@NOSPAMbetadome.com
(remove NOSPAM to contact me directly)

 

Navigation:

[Reply to this message]


УдалСнная Ρ€Π°Π±ΠΎΡ‚Π° для программистов  •  Как Π·Π°Ρ€Π°Π±ΠΎΡ‚Π°Ρ‚ΡŒ Π½Π° Google AdSense  •  England, UK  •  ΡΡ‚Π°Ρ‚ΡŒΠΈ Π½Π° английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Π‘Π°ΠΉΡ‚ ΠΈΠ·Π³ΠΎΡ‚ΠΎΠ²Π»Π΅Π½ Π² Π‘Ρ‚ΡƒΠ΄ΠΈΠΈ Π’Π°Π»Π΅Π½Ρ‚ΠΈΠ½Π° ΠŸΠ΅Ρ‚Ρ€ΡƒΡ‡Π΅ΠΊΠ°
ΠΈΠ·Π³ΠΎΡ‚ΠΎΠ²Π»Π΅Π½ΠΈΠ΅ ΠΈ ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΠ° Π²Π΅Π±-сайтов, Ρ€Π°Π·Ρ€Π°Π±ΠΎΡ‚ΠΊΠ° ΠΏΡ€ΠΎΠ³Ρ€Π°ΠΌΠΌΠ½ΠΎΠ³ΠΎ обСспСчСния, поисковая оптимизация