Talk:Code Injection

Revision as of 02:26, 15 July 2008 by Ratm owasp (Talk | contribs)

(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search

Is the php code injection example correct? I gave it more than one try on the php command line, and it doesn't seem to work. I think that this code snippet eval("\$myvar = \$x;");

is not exploitable, since the string that is evaluated is a constant. It works like a charm if you don't escape $x.