note 41088 added to function.preg-replace

From: Date: Mon, 29 Mar 2004 22:30:11 +0000
Subject: note 41088 added to function.preg-replace
Groups: php.notes 
Request: Send a blank email to php-notes+get-67347@lists.php.net to get a copy of this message
Massimo 20-Feb-2004 01:46 wrote: <?php // ... snip ... $msg = preg_replace("/\[(\w+)\]/e", "\$\\1", $str); ?> "The above script will produce the desired output replacing variables inside brackets with values in the php script." Doing this is not a very good idea, especially if you don't have full control of the text input. The problem with it is that you're likely to have variables you don't want made public (e.g., $password). Simply inserting a variable name in brackets will display it to the world. This is a major security problem, but won't matter if you're creating a small script for your own personal use, that will not be accessed by anyone else. Use at your own risk. ---- Manual Page -- http://www.php.net/manual/en/function.preg-replace.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+41088 Delete -- http://master.php.net/manage/user-notes.php?action=delete+41088&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+41088&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#67347) next »