note 41088 deleted from function.preg-replace by tularis

From: Date: Sun, 18 Jun 2006 13:19:47 +0000
Subject: note 41088 deleted from function.preg-replace by tularis
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-114327@lists.php.net to get a copy of this message
Note Submitter: thesaur at php dot net ---- Massimo 20-Feb-2004 01:46 wrote: <?php // ... snip ... $msg = preg_replace("/\[(\w+)\]/e", "\$\\1", $str); ?> "The above script will produce the desired output replacing variables inside brackets with values in the php script." Doing this is not a very good idea, especially if you don't have full control of the text input. The problem with it is that you're likely to have variables you don't want made public (e.g., $password). Simply inserting a variable name in brackets will display it to the world. This is a major security problem, but won't matter if you're creating a small script for your own personal use, that will not be accessed by anyone else. Use at your own risk.

« previous php.notes (#114327) next »