dqqlziv195281 2014-12-20 11:35
浏览 5
已采纳

哪个好php_self或phpfilename.php

friends can any body tell me which is good between php_self or phpfilename.php

some persons use in form action "$_SERVER[PHP_SELF]" and some use "updatedata.php" which one is good and why it is good

  • 写回答

2条回答 默认 最新

  • dreamer1231 2014-12-20 11:38
    关注

    You shouldn't use PHP_SELF its not really neaded the problem is if you echo that variable in a link for example you have XSS attack because all parameters are written to the site.

    PHP_SELF and XSS

    Here are some cool answers. So its better to use the complete name of the file and put the parameters you need filtered behind the filename.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(1条)

报告相同问题?

悬赏问题

  • ¥15 用友U8:向一个无法连接的网络尝试了一个套接字操作,如何解决?
  • ¥30 我的代码按理说完成了模型的搭建、训练、验证测试等工作(标签-网络|关键词-变化检测)
  • ¥50 mac mini外接显示器 画质字体模糊
  • ¥15 TLS1.2协议通信解密
  • ¥40 图书信息管理系统程序编写
  • ¥20 Qcustomplot缩小曲线形状问题
  • ¥15 企业资源规划ERP沙盘模拟
  • ¥15 树莓派控制机械臂传输命令报错,显示摄像头不存在
  • ¥15 前端echarts坐标轴问题
  • ¥15 ad5933的I2C