note 24180 added to function.eval

From: Date: Thu, 08 Aug 2002 16:45:09 +0000
Subject: note 24180 added to function.eval
Groups: php.notes 
Request: Send a blank email to php-notes+get-34538@lists.php.net to get a copy of this message
Nobody's mentioned this yet and I think a lot of newbies might not think of it, so here goes: Never EVER EVER eval() user input. This goes for GET, POST and COOKIE vars, as well as stuff in databases, files, etc which can be written by people other than you. Never do it. Why? Consider the following simple and obvious example: eval("\$user_input = \"$user_input\";"); If the user enters (note the quotes): ""; mysql_query('DROP DATABASE mysql') You'll lose your database. Needless to say, a user with control over PHP (even in safe mode) has way too much power over your computer. Obviously you're not logging into your database as root and obviously you're not that stupid, but just don't eval() user input anyway, 'cuz you never know :) -- http://www.php.net/manual/en/function.eval.php http://master.php.net/manage/user-notes.php?action=edit+24180 http://master.php.net/manage/user-notes.php?action=delete+24180 http://master.php.net/manage/user-notes.php?action=reject+24180

« previous php.notes (#34538) next »