Re: Eval use in XML_RPC

From: Date: Thu, 28 Jul 2005 20:13:55 +0000
Subject: Re: Eval use in XML_RPC
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-39007@lists.php.net to get a copy of this message
Joshua Eichorn wrote:
From my quick audit I see no area where it actual needs to be used, and just from a security standpoint I don't think eval should be allowed in Any PEAR code.
This statement is a little bit over zealous, static eval usage for php5 clone compatibaility is safe since the string doesn't come from user input. There might also be cases like the proxy generation in SOAP's WSDL class that won't work any other way. But still any use of eval from untrusted input should be avoided whenever possible. -josh

« previous php.pear.dev (#39007) next »