#39679 [NEW]: preg_replace with e modifier: design issue

From: Date: Wed, 29 Nov 2006 10:12:43 +0000
Subject: #39679 [NEW]: preg_replace with e modifier: design issue
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-105613@lists.php.net to get a copy of this message
From: silverbanana at gmx dot de Operating system: Any PHP version: 6CVS-2006-11-29 (CVS) PHP Bug Type: PCRE related Bug description: preg_replace with e modifier: design issue Description: ------------ preg_replace offers the e modifier to evaluate a replacement string as PHP code and use the result of that code for the replacement. This is a very powerful feature. There is, however one problem: If you want to get the string found by preg_replace things can get complicated, dangerous, even impossible: This should replace anything between a and b by giving it's strlen. $search[0]="/a(.*)b/e"; $replace[0]="strlen('\\1')"; $result=preg_replace($search, $replace, $_GET['in']); Obviously it is possible to do very bad things here, because $_GET['in'] might be a string like: "');dosthbad();$a=('". Expected result: ---------------- It would be good to have a predefined variable available inside the eval'ed PHP code, that just contains all the values for the parenthesis. Assume this is called $found. Then one could write something like this: $search[0]="/a(.*)b/e"; // same as before $replace[0]='strlen($found[1])'; // <- changed $result=preg_replace($search, $replace, $_GET['in']); // same And this time things would be safe. Possibly it might be useful to introduce this functionality under a different modifier, but I think it would be a significant improvement for many applications. -- Edit bug report at http://bugs.php.net/?id=39679&edit=1 -- Try a CVS snapshot (PHP 4.4): http://bugs.php.net/fix.php?id=39679&r=trysnapshot44 Try a CVS snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=39679&r=trysnapshot52 Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=39679&r=trysnapshot60 Fixed in CVS: http://bugs.php.net/fix.php?id=39679&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=39679&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=39679&r=needtrace Need Reproduce Script: http://bugs.php.net/fix.php?id=39679&r=needscript Try newer version: http://bugs.php.net/fix.php?id=39679&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=39679&r=support Expected behavior: http://bugs.php.net/fix.php?id=39679&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=39679&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=39679&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=39679&r=globals PHP 3 support discontinued: http://bugs.php.net/fix.php?id=39679&r=php3 Daylight Savings: http://bugs.php.net/fix.php?id=39679&r=dst IIS Stability: http://bugs.php.net/fix.php?id=39679&r=isapi Install GNU Sed: http://bugs.php.net/fix.php?id=39679&r=gnused Floating point limitations: http://bugs.php.net/fix.php?id=39679&r=float No Zend Extensions: http://bugs.php.net/fix.php?id=39679&r=nozend MySQL Configuration Error: http://bugs.php.net/fix.php?id=39679&r=mysqlcfg

« previous php.bugs (#105613) next »