note 19494 deleted from function.eval by sniper

From: Date: Thu, 29 Dec 2005 09:15:40 +0000
Subject: note 19494 deleted from function.eval by sniper
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-100916@lists.php.net to get a copy of this message
Note Submitter: nospam at 1111-internet dot com ---- Understanding the following concept should help users of the eval function: It appears that the first thing eval does internally before actually eval-ing is to sandwich the argument between the strings "<?php " (note the trailing space) and "?>" (with no spaces). This accounts for the following behavior (and some of the behaviors already cited by other users): <?php $ques="?"; $php_open="<${ques}php"; $php_close="${ques}>"; /////////////////////////////////// $text_string="Text string"; eval("$text_string"); /* interpreted as "<?php Text string?>" - parse error */ eval("$php_close$text_string$php_open"); /* interpreted as "<?php ?>Text string<?php?>" - parse error ("<?php?>" at the end) */ eval("$php_close$text_string$php_open "); // note the trailing space /* interpreted as "<?php ?>Text string<?php ?>" - desired result */ /////////////////////////////////// $code_string="echo 'Code string';"; eval("$code_string"); /* interpreted as "<?php echo 'Code string';?>" - desired result */ eval("$php_close$code_string$php_open"); /* interpreted as "<?php ?>echo 'Code string';<?php?>" - parse error ("<?php?>" at the end) */ eval("$php_close$code_string$php_open "); // note the trailing space /* interpreted as "<?php ?>echo 'Code string';<?php ?>" - no error, but probably not the desired result */ /////////////////////////////////// $code_string_with_php_tags="$php_open echo 'Code string'; $php_close"; eval("$code_string_with_php_tags"); /* interpreted as "<?php <?php echo 'Code string'; ?>?>" - parse error */ eval("$php_close$code_string_with_php_tags$php_open"); /* interpreted as "<?php ?><?php echo 'Code string'; ?><?php?>" - parse error ("<?php?>" at the end) */ eval("$php_close$code_string_with_php_tags$php_open "); // note the trailing space /* interpreted as "<?php ?><?php echo 'Code string'; ?><?php ?>" - desired result */ /////////////////////////////////// ?> Interestingly, the implicit eval done in the preg_replace function with the "e" switch seems to have a separate set of rules - sandwiching the replace argument between "return " and ";" (after running addslashes on any match references in the replace string - but I digress) before running the eval on it...

« previous php.notes (#100916) next »