Welcome Guest, Not a member yet? Register   Sign In
Insecure Form_validation rule "encode_php_tags"
#4

[eluser]Phil Sturgeon[/eluser]
The security issue is that this function is suppored to encode all PHP tags and it does not. If str_ireplace is out of the question the a simple regular expression would achieve the same goal.

It may be silly and I have never used this validation method, but this just doesn't do what it says on the tin. :-)

And yea Tim, I said the wrong thing... oops. >.<


Messages In This Thread
Insecure Form_validation rule "encode_php_tags" - by El Forum - 04-14-2009, 05:55 AM
Insecure Form_validation rule "encode_php_tags" - by El Forum - 04-14-2009, 08:50 AM
Insecure Form_validation rule "encode_php_tags" - by El Forum - 04-15-2009, 07:17 AM
Insecure Form_validation rule "encode_php_tags" - by El Forum - 04-20-2009, 09:30 AM
Insecure Form_validation rule "encode_php_tags" - by El Forum - 04-20-2009, 09:39 AM
Insecure Form_validation rule "encode_php_tags" - by El Forum - 04-20-2009, 09:49 AM
Insecure Form_validation rule "encode_php_tags" - by El Forum - 04-20-2009, 09:58 AM



Theme © iAndrew 2016 - Forum software by © MyBB