The previous article introduced you to "How to upload files in PHP? What do we need to pay attention to? 》, this article continues to introduce to you what are the vulnerabilities of commonly used functions in PHP? It has certain reference value. Friends in need can refer to it. I hope it will be helpful to everyone.
Vulnerabilities in commonly used functions in PHP:
extract variable coverage vulnerability
extract function: Import variables from the array into the current symbol table. It can be found in some mvc frameworks
Extract function definition: int extract(array,extract_ rules,prefix)
extract0 The function will check whether each key name is a legal variable name and also checks whether it conflicts with an existing variable name in the symbol table. The handling of illegal and conflicting key names will be determined based on this parameter.
extract_rules :
EXTR_ OVERWRITE - Default. If there is a conflict, existing variables are overwritten.
EXTR_ SKIP - If there is a conflict, do not overwrite existing variables.
EXTR_ PREFIX. SAME - If there is a conflict, add a prefix to the variable name.
EXTR_ PREFIX. ALL - Give all variable names Prefix prefix.
EXTR_ PREFIX. INVALID - Prefix only illegal or numeric variable names with prefix.
<?php $name = '好久不见'; echo $name; ?>
<?php $name = '好久不见'; extract(array('name'=>'再见')); echo $name; ?>
PHP video tutorial"
The above is the detailed content of What are the vulnerabilities of commonly used functions in PHP?. For more information, please follow other related articles on the PHP Chinese website!