> > Alternatively, $_SERVER['PHP_SELF']) could be switch()ed for known> > values, and $path be set accordingly with hardcoded values.>> Didn't notice this thread passing from the list. I will look into it.>> But sometimes you need to detect where something is located and that's the> point of the whole conversation. If you hardcode the values then you need to> change them while renaming or moving files and directories>> So what someone should do to accomplish such a behavior? Without being> vulnerable to injection attacks of course.> It's not vulnerable to injection in the sense that the attacker couldnot redirect the links to his site. At a maximum he could disable thelinks, but he could not redirect them. That's why I mean by hardcoded.