> > Alternatively, $_SERVER['PHP_SELF']) could be switch()ed for known> > values, and $path be set accordingly with hardcoded values.>> Didn't notice this thread passing from the list. I will look into it.>> But sometimes you need to detect where something is located and that's the> point of the whole conversation. If you hardcode the values then you need to> change them while renaming or moving files and directories>> So what someone should do to accomplish such a behavior? Without being> vulnerable to injection attacks of course.> It's not vulnerable to injection in the sense that the attacker couldnot redirect the links to his site. At a maximum he could disable thelinks, but he could not redirect them. That's why I mean by hardcoded. -- Dotan Cohen http://what-is-what.comhttp://gibberish.co.il א-ב-ג-ד-ה-ו-ז-ח-ט-י-ך-כ-ל-ם-מ-ן-נ-ס-ע-ף-פ-ץ-צ-ק-ר-ש-תا-ب-ت-ث-ج-ح-خ-د-ذ-ر-ز-س-ش-ص-ض-ط-ظ-ع-غ-ف-ق-ك-ل-م-ن-ه-و-يА-Б-В-Г-Д-Е-Ё-Ж-З-И-Й-К-Л-М-Н-О-П-Р-С-Т-У-Ф-Х-Ц-Ч-Ш-Щ-Ъ-Ы-Ь-Э-Ю-Яа-б-в-г-д-е-ё-ж-з-и-й-к-л-м-н-о-п-р-с-т-у-ф-х-ц-ч-ш-щ-ъ-ы-ь-э-ю-яä-ö-ü-ß-Ä-Ö-Ü