note 41088 deleted from function.preg-replace by tularis
| From: | tularis@php.net | Date: | Sun, 18 Jun 2006 13:19:47 +0000 |
| Subject: | note 41088 deleted from function.preg-replace by tularis | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-114327@lists.php.net to get a copy of this message | ||
Note Submitter: thesaur at php dot net
----
Massimo 20-Feb-2004 01:46 wrote:
<?php
// ... snip ...
$msg = preg_replace("/\[(\w+)\]/e", "\$\\1", $str);
?>
"The above script will produce the desired output replacing variables inside brackets with
values in the php script."
Doing this is not a very good idea, especially if you don't have full control of the text
input. The problem with it is that you're likely to have variables you don't want made
public (e.g., $password). Simply inserting a variable name in brackets will display it to the world.
This is a major security problem, but won't matter if you're creating a small script for
your own personal use, that will not be accessed by anyone else. Use at your own risk.