|
|
Choosing A Webhost: |
yet more suggestions for .73...: msg#00011cms.phpslash.devel
ummm it seems that posting code to an article causes phpslash to parse the code. This makes yet another suggestion for the future release: #. Do not parse code coming from articles. Things like having $php variables, or {VAR} containers for templates... They should all be escaped if the text comes from an article. That could potentially eliminate all types of cross-site scripting and sql-code injection that <i>might</i> be lurking in the phpslash code... At least people should have the option to turn code parsing off, in case somebody actually wants to allow this for his/her site. Suggestions? P.S. For the meantime I'll try to escape as much as I can by hand (as I usually do). ----)(----- Luis Mondesi System Administrator LatinoMixed.com lemsx1-PkbjNfxxIARBDgjK7y7TUQ@xxxxxxxxxxxxxxxx "...The Mac does this so smoothly, it feels like an extension of your mind." - Paula Speer, MacWorld Magazine 2003-04 Public signature: http://www.latinomixed.com/lems1/public-a.asc _________________________________________________________________ MSN Messenger : discutez en direct avec vos amis ! http://www.msn.fr/msger/default.asp ------------------------------------------------------- Enterprise Linux Forum Conference & Expo, June 4-6, 2003, Santa Clara The only event dedicated to issues related to Linux enterprise solutions www.enterpriselinuxforum.com
|
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: suggestions for .73?, Luis M |
|---|---|
| Next by Date: | Re: yet more suggestions for .73..., nathan r. hruby |
| Previous by Thread: | suggestions for .73?, Luis M |
| Next by Thread: | Re: yet more suggestions for .73..., nathan r. hruby |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
Free MagazinesCisco NewsReceive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business. subscribe Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field. subscribe The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business. subscribe Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company. subscribe Total Telecom Total Telecom is "The Economist of the communications industry". subscribe |
Home
| advertise | OSDir is
an inevitable website.
|