Re: Secure eval();
| From: | 1LT John W. Holmes | Date: | Tue, 21 May 2002 15:09:22 +0000 |
| Subject: | Re: Secure eval(); | ||
| References: | 1 2 3 4 5 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-98606@lists.php.net to get a copy of this message | ||
Why don't you just do it all in your query??
SELECT (({table1.field1} * {table2.field2}) + {table3.field3}) FROM table1,
table2, table3 WHERE ...
---John Holmes...
----- Original Message -----
From: "Chris Boget" <chris@wild.net>
To: "1LT John W. Holmes" <holmes072000@charter.net>; "PHP General"
<php-general@lists.php.net>
Sent: Tuesday, May 21, 2002 10:53 AM
Subject: Re: [PHP] Secure eval();
> > Are you sure you have to run it through eval()? It sounds like you're
> > creating a query. Couldn't you just create the query dynamically, then
put
> > it in a mysql_query() function? (or whatever DB you're using) Then, even
if
> > they try some kung fu on you, it'll just result in a bad query, not some
> > rogue code being executed.
>
> Try some kung fu? Never heard it put like that before. :P
>
> I am kind of creating a query. The equation is going to look something
like
> this:
>
> (({table1.field1} * {table2.field2}) + {table3.field3})
>
> Then I'm going to get the values in those fields and parse the above as if
they
> were macros (which, in a sense, they are). That could yield something
like:
>
> ((8 * 5) + 3)
>
> and it is that equation that I'm going to need to eval. So I don't think
I'll be able
> to do this in a query.
>
> Chris
>