Trace Trace - 3 years ago 103
PHP Question

How do I delete a member of $_REQUEST?


Array (
[action] => test
[city_name] => Orlando
[delete_me] => -

Can I just delete it or will setting it to
$_REQUEST['delete_me'] = "";
do the trick?

Answer Source

In addition to what halfdan said, you should probably be using $_GET or $_POST or equivalent, unless you really do require it to be that ambiguous.

Taking values from $_REQUEST can make XSS that much easier... when you want POST values and a malicious user just appends them to a query string.

Recommended from our users: Dynamic Network Monitoring from WhatsUp Gold from IPSwitch. Free Download