#39679 [NEW]: preg_replace with e modifier: design issue
| From: | silverbanana at gmx dot de | Date: | Wed, 29 Nov 2006 10:12:43 +0000 |
| Subject: | #39679 [NEW]: preg_replace with e modifier: design issue | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-105613@lists.php.net to get a copy of this message | ||
From: silverbanana at gmx dot de
Operating system: Any
PHP version: 6CVS-2006-11-29 (CVS)
PHP Bug Type: PCRE related
Bug description: preg_replace with e modifier: design issue
Description:
------------
preg_replace offers the e modifier to evaluate a replacement string as PHP
code and use the result of that code for the replacement. This is a very
powerful feature. There is, however one problem:
If you want to get the string found by preg_replace things can get
complicated, dangerous, even impossible:
This should replace anything between a and b by giving it's strlen.
$search[0]="/a(.*)b/e";
$replace[0]="strlen('\\1')";
$result=preg_replace($search, $replace, $_GET['in']);
Obviously it is possible to do very bad things here, because $_GET['in']
might be a string like: "');dosthbad();$a=('".
Expected result:
----------------
It would be good to have a predefined variable available inside the
eval'ed PHP code, that just contains all the values for the parenthesis.
Assume this is called $found. Then one could write something like this:
$search[0]="/a(.*)b/e"; // same as before
$replace[0]='strlen($found[1])'; // <- changed
$result=preg_replace($search, $replace, $_GET['in']); // same
And this time things would be safe. Possibly it might be useful to
introduce this functionality under a different modifier, but I think it
would be a significant improvement for many applications.
--
Edit bug report at http://bugs.php.net/?id=39679&edit=1
--
Try a CVS snapshot (PHP 4.4): http://bugs.php.net/fix.php?id=39679&r=trysnapshot44
Try a CVS snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=39679&r=trysnapshot52
Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=39679&r=trysnapshot60
Fixed in CVS: http://bugs.php.net/fix.php?id=39679&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=39679&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=39679&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=39679&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=39679&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=39679&r=support
Expected behavior: http://bugs.php.net/fix.php?id=39679&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=39679&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=39679&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=39679&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=39679&r=php3
Daylight Savings: http://bugs.php.net/fix.php?id=39679&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=39679&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=39679&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=39679&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=39679&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=39679&r=mysqlcfg