Eval use in XML_RPC
| From: | Joshua Eichorn | Date: | Thu, 28 Jul 2005 19:40:05 +0000 |
| Subject: | Eval use in XML_RPC | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-39005@lists.php.net to get a copy of this message | ||
After the last security problems in XML_RPC im surprised to see that no one has went and removed the use the eval from the code.
From my quick audit I see no area where it actual needs to be used, and just from a security standpoint I don't think eval should be allowed in Any PEAR code.
For example line 1629 of RPC.php is:
@eval('$b->'.$id.' = $cont;');
This can easily be replaced by
$b->$id = $cont;
eval is now removed so things run faster, plus there is no possible exploit from a poorly escaped value in $id
The other used of eval is at line 1331
@eval('$v=' . $XML_RPC_xh[$parser]['st'] . '; $allOK=1;');
This seems to be used mainly to handle complex data types like arrays, though even strings and objects are pushed through it. Removing this will take reworking the XML_RPC_se function so its not a simple one liner, but it shouldn't be that hard to redo if you know how the process actually works.
-josh