Zen Cart Logo
Forums / General Questions / PHP on EZ-Pages Safe or NOT?

PHP on EZ-Pages Safe or NOT?

Locked

Views: 755

Results 1 to 2 of 2
This thread is locked. New replies are disabled.
29 May 2008, 9:37 AM
#1
picci avatar

picci

Zen Follower

Join Date:
Feb 2006
Posts:
125
Plugin Contributions:
0

PHP on EZ-Pages Safe or NOT?

I want to use PHP code on some EZ-Pages. I found the code below on the forum that will enable PHP to be written to the database for the EZ-Pages:

<!-- PHP ENABLE CODE --> <div><?php eval(stripslashes('?>' . $var_pageDetails->fields['pages_html_text'])); ?></div> <!-- PHP ENABLE CODE END -->

Does anyone know if this method is safe to use or is it a potential security hole?

Are there other methods that are better for this?

1 Jun 2008, 10:38 AM
#2
picci avatar

picci

Zen Follower

Join Date:
Feb 2006
Posts:
125
Plugin Contributions:
0

Re: PHP on EZ-Pages Safe or NOT?

I googled around and found the following links on eval() and security:

http://www.php.net/eval

http://en.wikipedia.org/wiki/Eval

From what I gather the biggest risk is to allow unknown user generated content to be run through an eval(). They could run their own PHP scripts. For example if you had a form where an unknown user can input data, and that input data gets run through an eval(), the user could run their own PHP code through it.