#26569 [Fbk->NoF]: Backslash \ is removed with eval

From: Date: Mon, 15 Dec 2003 02:15:02 +0000
Subject: #26569 [Fbk->NoF]: Backslash \ is removed with eval
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-52055@lists.php.net to get a copy of this message
ID: 26569 Updated by: sniper@php.net Reported By: webmaster at acecoolco dot com -Status: Feedback +Status: No Feedback -Bug Type: Unknown/Other Function +Bug Type: Scripting Engine problem Operating System: Linux PHP Version: 4.3.3 New Comment: No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Open". Thank you. Previous Comments: ------------------------------------------------------------------------ [2003-12-09 17:53:19] eru@php.net Ok, we'll leave it at feedback, you can set it to open again when you provide the script. ------------------------------------------------------------------------ [2003-12-09 17:47:59] webmaster at acecoolco dot com Well, to template my pages, I use file_get_contents of the file, next I preg replace everything, then eval("?>" . $Template_IT . "<?"); $Template_IT = preg_replace(... Next, just a simple simple form, have it submit to the same page, no need to even insert it anywhere, the page will show up blank, and if the code had backslashes they will be stripped. Heres what I tried inserting: http://www.acecoolco.com/media_tutorialshow.php?id=28 It inserted fine, stripped the slashes even though it wasnt supposed to, and the resulting page, instead of a thank you page, I got a blank page. I will work on a basic script to show exactly what I mean, it will be in the next reply ------------------------------------------------------------------------ [2003-12-09 17:42:47] eru@php.net Thank you for this bug report. To properly diagnose the problem, we need a short but complete example script to be able to reproduce this bug ourselves. A proper reproducing script starts with <?php and ends with ?>, is max. 10-20 lines long and does not require any external resources such as databases, etc. If possible, make the script source available online and provide an URL to it here. Try avoid embedding huge scripts into the report. ------------------------------------------------------------------------ [2003-12-09 17:10:12] webmaster at acecoolco dot com Description: ------------ Ive finally traced this bug. If you have a page generated with EVAL Ok, I have a form, when you submit it, it adds code to mysql database, it works, but using EVAL, it removes \s I saw the other bug report saying highlight_string removes the backslashes, this is NOT the case. sites using EVAL, eval removes the backslash, vbb uses eval, it removes the \ on submission. I used to use eval, it removed the backslash on submit. Reproduce code: --------------- $patterns[] = "/{ACWB_DISPLAYPAGELOADTIME}/"; $contents[] = "$DisplayPageLoadTime"; $Template_IT = @preg_replace($patterns, $contents, $string); echo $Template_IT; // I have taken out Eval due to possible security flaws... /* @eval("?>" . $Template_IT . "<?"); */ Expected result: ---------------- Nothing, its just a small snippet Actual result: -------------- . ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=26569&edit=1

« previous php.bugs (#52055) next »