Jump to content

[SOLVED] get['view']


whiteboikyle

Recommended Posts

Okay i have a view.php file that has something like

 

<?php
include("header.inc");
if(!$_GET['view']) 
    {
        header("location:index.php");
    }
else
     {
   include($_GET['view']); 
    }

include("footer.inc");

?>

 

So i go to localhost/kazi/view.php?view=aboutus.inc

It shows up like

TEST Test test

 

instead of

TEST

Test

test

 

when its typed like that in the about us

 

 

Well i tried

 

nl2br();

but it wont seem to work on this..

Link to comment
https://forums.phpfreaks.com/topic/98924-solved-getview/
Share on other sites

first of all, you have a major security error:

 

localhost/kazi/view.php?view=aboutus.inc

//Do not let user to freely enter the file you want to include. This is exatly you did though url.

 

You could try something like this:

http://www.sebastiansulinski.co.uk/web_design_tutorials/php/php_url_parameter.php

Link to comment
https://forums.phpfreaks.com/topic/98924-solved-getview/#findComment-506159
Share on other sites

No i have it secured on other pages..

But what i am trying to do is

aboutus.inc is a plain txt file and what ever is in there shows up on the page..

Well when going to edit it in the user console you have to type html codes for it to break..

but i want it to break on its own when you press enter (new line)

Link to comment
https://forums.phpfreaks.com/topic/98924-solved-getview/#findComment-506195
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.