note 33522 deleted from function.eval by didou
| From: | didou@php.net | Date: | Sun, 27 Jul 2003 17:02:14 +0000 |
| Subject: | note 33522 deleted from function.eval by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-52767@lists.php.net to get a copy of this message | ||
Note Submitter: geoffrey@sickphp.com
----
[Editor's Note: The following is a prime example of how NOT to use eval(). Apart from the
gaping security hole this opens, it can more simply be done with: $final =
${$_GET['term']}['left']; The author would be advised to read the manual
section on "Variable Variables". ]
interesting thing about eval, you can use passed vars, turn them into literals and use the values
for function arguments. sorry if this has already been done on this board:
//getvar: $_GET['term'] = "victory";
<?
//victory vars file
$victory['left'] = "works!"; // this would be in a separate file.
so you would need the "term"
from _GET to know what to do.
?>
<?
//mainfile
include_once("victory.inc");
$string = "\$_GET['term']";
eval("\$module = \"$\".$string.\"['left']\";");
eval("\$final = $module;");
echo $final;
?>
is there an easier way to do this? if you can understand my rambling ...