This page is not yet available in Spanish. We are working on its translation. If you have any questions or feedback about our current translation project, feel free to reach out to us!
The extract() function in PHP can be used to import variables into the local symbol table from an array. However, using it on untrusted data, such as user input, can lead to a variety of security vulnerabilities, including arbitrary code execution and SQL injection, making it a dangerous practice.
By using extract() on untrusted data, you may inadvertently create variables that overwrite important ones, or worse, you could execute harmful code that was injected by a malicious user.
To adhere to this rule, you should explicitly assign and sanitize user input rather than using extract(). This will ensure your code remains secure and compliant.
Non-Compliant Code Examples
<?php// Insecure: Using extract() on untrusted data from $_GET
extract($_GET);echo"Hello, $name!";// Insecure: Using extract() on untrusted data from $_POST
extract($_POST);if($isAdmin){echo"Welcome, admin!";}else{echo"Welcome, user!";}// Insecure: Using extract() on untrusted data from $_FILES
extract($_FILES['uploadedFile']);if(move_uploaded_file($tmp_name,"uploads/$name")){echo"File uploaded successfully!";}else{echo"File upload failed.";}?>
Compliant Code Examples
<?php// Secure: Explicitly assign and sanitize user input
$name=htmlspecialchars($_GET['name'],ENT_QUOTES,'UTF-8');echo"Hello, $name!";// Secure: Explicitly assign and validate user input
$isAdmin=isset($_POST['isAdmin'])&&$_POST['isAdmin']=='1';if($isAdmin){echo"Welcome, admin!";}else{echo"Welcome, user!";}// Secure: Explicitly handle file upload variables and validate
$file=$_FILES['uploadedFile'];$uploadDir='uploads/';$uploadFile=$uploadDir.basename($file['name']);if(move_uploaded_file($file['tmp_name'],$uploadFile)){echo"File uploaded successfully!";}else{echo"File upload failed.";}?>
Integraciones sin problemas. Prueba Datadog Code Security
Datadog Code Security
Prueba esta regla y analiza tu código con Datadog Code Security
Cómo usar esta regla
1
2
rulesets:- php-security # Rules to enforce PHP security.
Crea un static-analysis.datadog.yml con el contenido anterior en la raíz de tu repositorio
Utiliza nuestros complementos del IDE gratuitos o añade análisis de Code Security a tus pipelines de CI.