note 24180 added to function.eval
| From: | adamhooper at videotron dot ca | Date: | Thu, 08 Aug 2002 16:45:09 +0000 |
| Subject: | note 24180 added to function.eval | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-34538@lists.php.net to get a copy of this message | ||
Nobody's mentioned this yet and I think a lot of newbies might not think of it, so here goes:
Never EVER EVER eval() user input. This goes for GET, POST and COOKIE vars, as well as stuff in
databases, files, etc which can be written by people other than you. Never do it. Why? Consider the
following simple and obvious example:
eval("\$user_input = \"$user_input\";");
If the user enters (note the quotes):
""; mysql_query('DROP DATABASE mysql')
You'll lose your database. Needless to say, a user with control over PHP (even in safe mode)
has way too much power over your computer.
Obviously you're not logging into your database as root and obviously you're not that
stupid, but just don't eval() user input anyway, 'cuz you never know :)
--
http://www.php.net/manual/en/function.eval.php
http://master.php.net/manage/user-notes.php?action=edit+24180
http://master.php.net/manage/user-notes.php?action=delete+24180
http://master.php.net/manage/user-notes.php?action=reject+24180