PHP Developers Network

A community of PHP developers offering assistance, advice, discussion, and friendship.
 
Loading
It is currently Thu Jul 09, 2020 11:03 pm

All times are UTC - 5 hours




Post new topic Reply to topic  [ 4 posts ] 
Author Message
PostPosted: Thu Mar 10, 2005 7:10 pm 
Offline
DevNet Resident

Joined: Thu Mar 10, 2005 6:27 pm
Posts: 1027
Location: Southern Ontario
I'd appreciate it if someone could check this tiny function for any holes that I can't think of.
Syntax: [ Download ] [ Hide ]
function getPage($page, $default="about", $ext=".html") {

   if (!$page || !file_exists("./".$page.$ext)) $page=$default;

   return $page.$ext;

}


It's use is probably quite obvious. I use it for selecting the page to be included on the main index page by $_GET. This way, only one page containing the layout of the site is needed. I know that using a switch would be 100% secure, however on some sites that i design, there are dozen's of pages that need to be linked to, and doing it this way saves typing :)

usage: <link>/index.php?page=blah
Syntax: [ Download ] [ Hide ]
include(getPage($_GET['page']));


Top
 Profile  
 
 Post subject:
PostPosted: Thu Mar 10, 2005 7:24 pm 
Offline
Neighborhood Spidermoddy
User avatar

Joined: Mon Mar 29, 2004 4:24 pm
Posts: 31559
Location: Bothell, Washington, USA
it's quite possibly insecure. I could include a file you don't necessarily want to include, or if you provide an upload area I could introduce a properly encoded file that'd run like a normal script.

I'd recommend having a known list of valid, safe files to include, and use that..


Top
 Profile  
 
 Post subject:
PostPosted: Thu Mar 10, 2005 7:59 pm 
Offline
DevNet Resident

Joined: Thu Mar 10, 2005 6:27 pm
Posts: 1027
Location: Southern Ontario


Top
 Profile  
 
 Post subject:
PostPosted: Thu Mar 10, 2005 8:07 pm 
Offline
Neighborhood Spidermoddy
User avatar

Joined: Mon Mar 29, 2004 4:24 pm
Posts: 31559
Location: Bothell, Washington, USA


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 7 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group