note 33522 deleted from function.eval by didou

From: Date: Sun, 27 Jul 2003 17:02:14 +0000
Subject: note 33522 deleted from function.eval by didou
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-52767@lists.php.net to get a copy of this message
Note Submitter: geoffrey@sickphp.com ---- [Editor's Note: The following is a prime example of how NOT to use eval(). Apart from the gaping security hole this opens, it can more simply be done with: $final = ${$_GET['term']}['left']; The author would be advised to read the manual section on "Variable Variables". ] interesting thing about eval, you can use passed vars, turn them into literals and use the values for function arguments. sorry if this has already been done on this board: //getvar: $_GET['term'] = "victory"; <? //victory vars file $victory['left'] = "works!"; // this would be in a separate file. so you would need the "term" from _GET to know what to do. ?> <? //mainfile include_once("victory.inc"); $string = "\$_GET['term']"; eval("\$module = \"$\".$string.\"['left']\";"); eval("\$final = $module;"); echo $final; ?> is there an easier way to do this? if you can understand my rambling ...

« previous php.notes (#52767) next »