View Single Post
Old 02-07-2006, 07:18 PM  
BoyAlley
So Fucking Gay
 
Join Date: Nov 2004
Posts: 19,714
NEVER trust input into a php script like that.

Simply using <?=$_GET["id"]?> alone is NOT a safe way to do this!

You're setting yourself up to get the living hell hacked out of you.

The variable MUST have something in place to parse out the possible crap from the input before utilizing the variable.

Last edited by BoyAlley; 02-07-2006 at 07:20 PM..
BoyAlley is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote