View Single Post
Old 02-07-2006, 07:19 PM  
After Shock Media
It's coming look busy
 
After Shock Media's Avatar
 
Join Date: Mar 2001
Location: "Ph'nglui mglw'nafh Cthulhu R'lyeh wgah'nagl fhtagn".
Posts: 35,299
Quote:
Originally Posted by BoyAlley
NEVER trust input into a php script like that.

Simply using <?=$_GET["id"]?> alone is NOT a safe way to do this!

You're setting yourself to get the living hell hacked out of you.

The variable MUST have something in place to parse out the crap from the input before echoing out a variable like that.
point taken, I am not a coder.
__________________

[email protected] ICQ:135982156 AIM: Aftershockmed1a MSN: [email protected]
After Shock Media is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote