note 68312 added to function.eval

From: Date: Fri, 21 Jul 2006 20:17:40 +0000
Subject: note 68312 added to function.eval
Groups: php.notes 
Request: Send a blank email to php-notes+get-115026@lists.php.net to get a copy of this message
Well let me just start off by saying that eval(); confused the heck out of me untill I read that you can use Return. This will help anyone who wants to "Inject" code into an IF statement. My example is a survey site, some questions are required, some are only required if others are checked. So let me share with you my dynamic script and show you how I was able to make a Dynamic IF Statement. The code below had been altered to be understandable. <?php $survey_number = 3 // The third survey. (Out of 10 Surveys) $rq[3] = array(1,2,3,4,5,6,8,9,11,13,15,17,19,20); // Required Questions for Survey 3 - Some of these can not be "NULL" (not NULL) or they will stop the script from going any further. (In my script I replaced any questions that were not answered with "NULL" using a for loop based on the number of questions in the survey) $aa[3][4] = ' && '.$q[3].' == "1"'; // Added Arguments - 3 = Survey 3's Arguments, 4= Argument belongs to question 4, $q[1-20] (20 Questions total in this case. //HERE IS THE DYNAMIC IF STATEMENT $count = count($rq[$survey_number]); for ($i=0;$i< $count;$i++) { $if_statement = '$q['.$rq[$survey_number][$i].'] == "NULL"'; if(isset($aa[$survey_number][$rq[$survey_number][$i]])) { $if_statement .= $aa[$survey_number][$rq[$survey_number][$i]]; } if(eval("return ".$if_statement.";")) { echo $rq[$survey_number][$i].': Is NULL and IS NOT ok.<br>'; } else { echo $rq[$survey_number][$i].': Is NULL and IS ok.<br>'; } } ?> In my experiance with this the Added Argument needs to have an actual value inplanted into the string, it did not work by just putting $q[3], i had to use '.$q[3].' to place the value of question 3 in the string. I hope this help someone, I spent so much time trying to figure this out and want to share how something this simple is done. Thank you. ---- Server IP: 64.71.164.2 Probable Submitter: 24.247.240.93 ---- X-Spam-Status: No, hits=3.3 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER, HTML_MESSAGE autolearn=no version=2.64 ---- Manual Page -- http://www.php.net/manual/en/function.eval.php Edit -- http://master.php.net/note/edit/68312 Del: integrated -- http://master.php.net/note/delete/68312/integrated Del: useless -- http://master.php.net/note/delete/68312/useless Del: bad code -- http://master.php.net/note/delete/68312/bad+code Del: spam -- http://master.php.net/note/delete/68312/spam Del: non-english -- http://master.php.net/note/delete/68312/non-english Del: in docs -- http://master.php.net/note/delete/68312/in+docs Del: other reasons-- http://master.php.net/note/delete/68312 Reject -- http://master.php.net/note/reject/68312 Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#115026) next »