[php-src] Issue #9663: add preg_quote_replacement() function
| From: | tomasfejfar | Date: | Mon, 03 Oct 2022 13:05:42 +0000 |
| Subject: | [php-src] Issue #9663: add preg_quote_replacement() function | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-242516@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/9663
Author: tomasfejfar
### Description
```php
$pattern = '/[[name]]/';
$template = 'My name is [[name]]';
preg_replace($pattern, $_POST['name'], $template);
```
This is prone to injection of any match from the pattern if user supplies for example
Tomas$1Fejfar. There is a preg_quote function that can be used to escape special chars
in template. There should be same function that would escape the replacement.
```
preg_quote_replacement($_POST['name']); // Tomas\$1Fejfar
```
IMHO it is enough to escape backslash and dollars with backslash, but I am not sure.
Currently the replacement must be escaped using userland function that makes it prone to mistakes.