Re: Eval use in XML_RPC
| From: | Joshua Eichorn | Date: | Thu, 28 Jul 2005 20:13:55 +0000 |
| Subject: | Re: Eval use in XML_RPC | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-39007@lists.php.net to get a copy of this message | ||
Joshua Eichorn wrote:
From my quick audit I see no area where it actual needs to be used, and just from a security standpoint I don't think eval should be allowed in Any PEAR code.This statement is a little bit over zealous, static eval usage for php5 clone compatibaility is safe since the string doesn't come from user input. There might also be cases like the proxy generation in SOAP's WSDL class that won't work any other way. But still any use of eval from untrusted input should be avoided whenever possible. -josh