#47797 [Opn->Bgs]: Security vulnerability in preg_replace is not documented clearly enough
ID: 47797
Updated by: fa@php.net
Reported By: spam04 at pornel dot net
-Status: Open
+Status: Bogus
Bug Type: Documentation problem
Operating System: *
PHP Version: Irrelevant
New Comment:
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
Previous Comments:
------------------------------------------------------------------------
[2009-03-26 23:38:17] spam04 at pornel dot net
Description:
------------
Re bug #47796:
Documentation for preg_replace only suggests to check PHP's string
syntax in non-alarming way.
Given that replacement code with double quotes (which is even used in
manual itself) could enable remote code execution, there should be a
clearly worded and highlighted warning about this.
The fragment "This is done to ensure that no syntax errors arise from
backreference usage with either single or double quotes" could lead
readers to believe that PHP escapes strings thoroughly and properly.
That is not the case:
preg_replace('/.*/e','"$0"', '{$foo[}');
Expected result:
----------------
Huge red box in manual with "Don't use /e".
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=47797&edit=1
Thread (2 messages)