<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>Comments on: Why allow_url_include is evil</title>
	<atom:link href="https://wiki.webhostingbuzz.com/why-allow_url_include-evil/feed/" rel="self" type="application/rss+xml" />
	<link>https://wiki.webhostingbuzz.com/why-allow_url_include-evil/</link>
	<description>[not used]</description>
	<lastBuildDate>Sat, 11 Jan 2025 20:41:00 +0000</lastBuildDate>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=3.9.40</generator>
	<item>
		<title>By: Nathan P.</title>
		<link>https://wiki.webhostingbuzz.com/why-allow_url_include-evil/#comment-23</link>
		<dc:creator><![CDATA[Nathan P.]]></dc:creator>
		<pubDate>Sun, 20 Mar 2016 05:43:00 +0000</pubDate>
		<guid isPermaLink="false">https://www.webhostingbuzz.com/wiki/?p=981#comment-23</guid>
		<description><![CDATA[But if you change the method of the include from GET to POST, the url injection is ignored.  Granted, the session cannot be &quot;bookmarked&quot; which removes ease of use depending on what you&#039;re making, but if your application writes to MySQL or another DB any data a user has remains server-side anyway.]]></description>
		<content:encoded><![CDATA[<p>But if you change the method of the include from GET to POST, the url injection is ignored.  Granted, the session cannot be &#8220;bookmarked&#8221; which removes ease of use depending on what you&#8217;re making, but if your application writes to MySQL or another DB any data a user has remains server-side anyway.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
