note 33522 modified in function.eval by pollita
| From: | pollita@php.net | Date: | Mon, 30 Jun 2003 01:51:44 +0000 |
| Subject: | note 33522 modified in function.eval by pollita | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-51174@lists.php.net to get a copy of this message | ||
[Editor's Note: The following is a prime example of how NOT to use eval(). Apart from the
gaping security hole this opens, it can more simply be done with: $final =
${$_GET['term']}['left']; The author would be advised to read the manual
section on "Variable Variables". ]
interesting thing about eval, you can use passed vars, turn them into literals and use the values
for function arguments. sorry if this has already been done on this board:
//getvar: $_GET['term'] = "victory";
<?
//victory vars file
$victory['left'] = "works!"; // this would be in a separate file.
so you would need the "term"
from _GET to know what to do.
?>
<?
//mainfile
include_once("victory.inc");
$string = "\$_GET['term']";
eval("\$module = \"$\".$string.\"['left']\";");
eval("\$final = $module;");
echo $final;
?>
is there an easier way to do this? if you can understand my rambling ...
--was--
interesting thing about eval, you can use passed vars, turn them into literals and use the values
for function arguments. sorry if this has already been done on this board:
//getvar: $_GET['term'] = "victory";
<?
//victory vars file
$victory['left'] = "works!"; // this would be in a separate file.
so you would need the "term"
from _GET to know what to do.
?>
<?
//mainfile
include_once("victory.inc");
$string = "\$_GET['term']";
eval("\$module = \"$\".$string.\"['left']\";");
eval("\$final = $module;");
echo $final;
?>
is there an easier way to do this? if you can understand my rambling ...
http://www.php.net/manual/en/function.eval.php