PHP 4.0 Bug #3256: eval & serialized data
| From: | anton at concord dot ru | Date: | Wed, 19 Jan 2000 22:19:31 +0000 |
| Subject: | PHP 4.0 Bug #3256: eval & serialized data | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-14764@lists.php.net to get a copy of this message | ||
From: anton@concord.ru
Operating system: NT 4.0+IIS 4.0
PHP version: 4.0 Beta 3
PHP Bug Type: Scripting Engine problem
Bug description: eval & serialized data
I use in my script serialized data from database, for example, data which was serialized by function
'serialize' set in 'DATA' field.
Sample code:
...
$Ser=mssql_result($MyResult,0,"DATA");
eval("\$Over=\$Ser;");
...
Parser error is occured after dinamic code evaluation.
As you wrote in incompatible features list '{' and '}' symbols used for string
encapsulation. But same symbols used as delimiters in serialization value. I changed souse code of
'serialize' and 'unserialize' functions. I Changed '{' and
'}' delimiters to '[' and ']' delimiters. After rebuild sample code
written above work without errors.