Bug->Doc #63854 [Opn->Wfx]: PHP 5.3.15
| From: | aharvey@php.net | Date: | Tue, 08 Jan 2013 03:04:18 +0000 |
| Subject: | Bug->Doc #63854 [Opn->Wfx]: PHP 5.3.15 | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-9367@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=63854&edit=1
ID: 63854
Updated by: aharvey@php.net
Reported by: spaghetti dot coder dot ru at gmail dot com
Summary: PHP 5.3.15
-Status: Open
+Status: Wont fix
-Type: Bug
+Type: Documentation Problem
Package: Documentation problem
Operating System: OS X 1.7.5, Win 7
PHP Version: 5.3Git-2012-12-26 (Git)
Block user comment: N
Private report: N
New Comment:
The regex given really only refers to the permitted characters in direct variable tokens ($foo)
â you can always do things via indirect methods such as variable variables and $GLOBALS that
don't conform to that.
Previous Comments:
------------------------------------------------------------------------
[2012-12-26 14:35:31] spaghetti dot coder dot ru at gmail dot com
In the same manner we can damage $this variable in a class
php > class MyClass {
php { public function __construct() {
php { // ${'this'} = 'broken'; // will give us a fatal error
php { $breakThis = 'this';
php { $$breakThis = 'broken'; // but this will serve fine
php { var_dump($this);
php { }
php { }
php > new MyClass();
string(6) "broken"
------------------------------------------------------------------------
[2012-12-26 12:33:40] spaghetti dot coder dot ru at gmail dot com
Description:
------------
---
From manual page: http://www.php.net/language.variables.basics
---
It's still possible to create a variable violation the [a-zA-Z_\x7f-\xff][a-zA-Z0-9_\x7f-\xff]*
rule
Test script:
---------------
<?php
// $*noWay = ''; // PHP Parse error: parse error, expecting
T_VARIABLE' or
'$'' in php shell code on line 1
$hackIt = '*iAmASiPointer!!!';
$$hackIt = 'Howdy';
echo $$hackIt;
echo "\n";
var_dump(get_defined_vars());
Expected result:
----------------
$$hackIt = 'Howdy'; line was supposed to trigger a PHP Parse error
Actual result:
--------------
Outputs:
Howdy
array(10) {
...
["hackIt"]=>
string(17) "*iAmASiPointer!!!"
["*iAmASiPointer!!!"]=>
string(4) "Howdy"
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=63854&edit=1