preg_replace oddity

From: Date: Fri, 31 Jan 2003 02:49:45 +0000
Subject: preg_replace oddity
Groups: php.dev 
Request: Send a blank email to php-dev+get-93829@lists.php.net to get a copy of this message
Can someone explain what is going on here: --- foo.php --- <?php $a = "___! 52); echo(42 !___"; $b = preg_replace("/!(.*)!/e", "print(\\1);", $a); print("\n---\na: $a\nb: $b\n"); ?> --- end --- --- output --- 52 --- a: ___! 52); echo(42 !___ b: ___1___ --- end --- I understand that one is supposed to use single quotes around the \\1 in the above preg_replace. But what happens when they do not? Clearly the echo(42); is not executed, and it is not printed by print(). Even more interesting is if you put something like echo(\"42 in $a, then you get a bunch of errors including: Fatal error - Failed evaluating code: print( 52); echo(\"42 ); It seems like preg_replace() is doing some strange things, and might be something that could be exploitable if a remote user can supply the first argument, and the second argument does not enclose \\n options. -James

« previous php.dev (#93829) next »