I’ve been told that it is unsecure to make database connections inside a PHP includes. For example If I have a login page and add an “include(‘process.php’)” at the top of the page that has a database connection, is that unsecure?
Share
Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.
Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.
Lost your password? Please enter your email address. You will receive a link and will create a new password via email.
Please briefly explain why you feel this question should be reported.
Please briefly explain why you feel this answer should be reported.
Please briefly explain why you feel this user should be reported.
No.
Maybe the person who told you this was talking about something else – like including a file using a dynamic value coming from a GET parameter, or using remote
http://includes, or as @AlienWebguy mentions, having the password include inside the web root. But using includes in itself is not insecure.