Eval - Manual - PHP

update page now
  • Downloads
  • Documentation
  • Get Involved
  • Help
  • PHP 8.5
Search docs PHP 8.1.34 Released! Getting Started Introduction A simple tutorial Language Reference Basic syntax Types Variables Constants Expressions Operators Control Structures Functions Classes and Objects Namespaces Enumerations Errors Exceptions Fibers Generators Attributes References Explained Predefined Variables Predefined Exceptions Predefined Interfaces and Classes Predefined Attributes Context options and parameters Supported Protocols and Wrappers Security Introduction General considerations Installed as CGI binary Installed as an Apache module Session Security Filesystem Security Database Security Error Reporting User Submitted Data Hiding PHP Keeping Current Features HTTP authentication with PHP Cookies Sessions Handling file uploads Using remote files Connection handling Persistent Database Connections Command line usage Garbage Collection DTrace Dynamic Tracing Function Reference Affecting PHP's Behaviour Audio Formats Manipulation Authentication Services Command Line Specific Extensions Compression and Archive Extensions Cryptography Extensions Database Extensions Date and Time Related Extensions File System Related Extensions Human Language and Character Encoding Support Image Processing and Generation Mail Related Extensions Mathematical Extensions Non-Text MIME Output Process Control Extensions Other Basic Extensions Other Services Search Engine Extensions Server Specific Extensions Session Extensions Text Processing Variable and Type Related Extensions Web Services Windows Only Extensions XML Manipulation GUI Extensions Keyboard Shortcuts? This help j Next menu item k Previous menu item g p Previous man page g n Next man page G Scroll to bottom g g Scroll to top g h Goto homepage g s Goto search(current page) / Focus search box exit » « die
  • PHP Manual
  • Function Reference
  • Other Basic Extensions
  • Misc.
  • Misc. Functions
Change language: English German Spanish French Italian Japanese Brazilian Portuguese Russian Turkish Ukrainian Chinese (Simplified) Other eval

(PHP 4, PHP 5, PHP 7, PHP 8)

evalEvaluate a string as PHP code

Description

eval(string $code): mixed

Evaluates the given code as PHP.

The code being evaluated inherits the variable scope of the line on which the eval() call occurs. Any variables available at that line will be available for reading and modification in the evaluated code. However, all functions and classes defined will be defined in the global namespace. In other words, the compiler considers the evaluated code as if it were a separate included file.

Caution

The eval() language construct is very dangerous because it allows execution of arbitrary PHP code. Its use thus is discouraged. If you have carefully verified that there is no other option than to use this construct, pay special attention not to pass any user provided data into it without properly validating it beforehand.

Parameters

code

Valid PHP code to be evaluated.

The code must not be wrapped in opening and closing PHP tags, i.e. 'echo "Hi!";' must be passed instead of '<?php echo "Hi!"; ?>'. It is still possible to leave and re-enter PHP mode though using the appropriate PHP tags, e.g. 'echo "In PHP mode!"; ?>In HTML mode!<?php echo "Back in PHP mode!";'.

Apart from that the passed code must be valid PHP. This includes that all statements must be properly terminated using a semicolon. 'echo "Hi!"' for example will cause a parse error, whereas 'echo "Hi!";' will work.

A return statement will immediately terminate the evaluation of the code.

The code will be executed in the scope of the code calling eval(). Thus any variables defined or changed in the eval() call will remain visible after it terminates.

Return Values

eval() returns null unless return is called in the evaluated code, in which case the value passed to return is returned. As of PHP 7, if there is a parse error in the evaluated code, eval() throws a ParseError exception. Before PHP 7, in this case eval() returned false and execution of the following code continued normally. It is not possible to catch a parse error in eval() using set_error_handler().

Examples

Example #1 eval() example - simple text merge

<?php$string = 'cup';$name = 'coffee';$str = 'This is a $string with my $name in it.';echo $str. "\n";eval("\$str = \"$str\";");echo $str. "\n";?>

The above example will output:

This is a $string with my $name in it. This is a cup with my coffee in it.

Notes

Note: Because this is a language construct and not a function, it cannot be called using variable functions, or named arguments.

Tip

As with anything that outputs its result directly to the browser, the output-control functions can be used to capture the output of this function, and save it in a string (for example).

Note:

In case of a fatal error in the evaluated code, the whole script exits.

See Also

  • call_user_func() - Call the callback given by the first parameter

Found A Problem?

Learn How To Improve This Page • Submit a Pull Request • Report a Bug +add a note

User Contributed Notes 7 notes

up down 487 Anonymous21 years ago Kepp the following Quote in mind: If eval() is the answer, you're almost certainly asking the wrong question. -- Rasmus Lerdorf, BDFL of PHP up down 44 lord dot dracon at gmail dot com10 years ago Inception with eval() <pre> Inception Start: <?php eval("echo 'Inception lvl 1...\n'; eval('echo \"Inception lvl 2...\n\"; eval(\"echo \'Inception lvl 3...\n\'; eval(\'echo \\\"Limbo!\\\";\');\");');"); ?> up down 21 Jeremie LEGRAND8 years ago At least in PHP 7.1+, eval() terminates the script if the evaluated code generate a fatal error. For example: <?php @eval('$content = (100 - );'); ?> (Even if it is in the man, I'm note sure it acted like this in 5.6, but whatever) To catch it, I had to do: <?php try { eval('$content = (100 - );'); } catch (Throwable $t) { $content = null; } ?> This is the only way I found to catch the error and hide the fact there was one. up down 29 bohwaz13 years ago If you want to allow math input and make sure that the input is proper mathematics and not some hacking code, you can try this: <?php $test = '2+3*pi'; // Remove whitespaces $test = preg_replace('/\s+/', '', $test); $number = '(?:\d+(?:[,.]\d+)?|pi|π)'; // What is a number $functions = '(?:sinh?|cosh?|tanh?|abs|acosh?|asinh?|atanh?|exp|log10|deg2rad|rad2deg|sqrt|ceil|floor|round)'; // Allowed PHP functions $operators = '[+\/*\^%-]'; // Allowed math operators $regexp = '/^(('.$number.'|'.$functions.'\s*\((?1)+\)|\((?1)+\))(?:'.$operators.'(?2))?)+$/'; // Final regexp, heavily using recursive patterns if (preg_match($regexp, $q)) { $test = preg_replace('!pi|π!', 'pi()', $test); // Replace pi with pi function eval('$result = '.$test.';'); } else { $result = false; } ?> I can't guarantee you absolutely that this will block every possible malicious code nor that it will block malformed code, but that's better than the matheval function below which will allow malformed code like '2+2+' which will throw an error. up down 8 catgirl at charuru dot moe8 years ago It should be noted that imported namespaces are not available in eval. up down 8 darkhogg (foo) gmail (bar) com15 years ago The following code <?php eval( '?> foo <?php' ); ?> does not throw any error, but prints the opening tag. Adding a space after the open tag fixes it: <?php eval( '?> foo <?php ' ); ?> up down 4 divinity76 at gmail dot com8 years ago imo, this is a better eval replacement: <?php function betterEval($code) { $tmp = tmpfile (); $tmpf = stream_get_meta_data ( $tmp ); $tmpf = $tmpf ['uri']; fwrite ( $tmp, $code ); $ret = include ($tmpf); fclose ( $tmp ); return $ret; } ?> - why? betterEval follows normal php opening and closing tag conventions, there's no need to strip `<?php?>` from the source. and it always throws a ParseError if there was a parse error, instead of returning false (note: this was fixed for normal eval() in php 7.0). - and there's also something about exception backtraces +add a note
  • Misc. Functions
    • connection_​aborted
    • connection_​status
    • constant
    • define
    • defined
    • die
    • eval
    • exit
    • get_​browser
    • _​_​halt_​compiler
    • highlight_​file
    • highlight_​string
    • hrtime
    • ignore_​user_​abort
    • pack
    • php_​strip_​whitespace
    • sapi_​windows_​cp_​conv
    • sapi_​windows_​cp_​get
    • sapi_​windows_​cp_​is_​utf8
    • sapi_​windows_​cp_​set
    • sapi_​windows_​generate_​ctrl_​event
    • sapi_​windows_​set_​ctrl_​handler
    • sapi_​windows_​vt100_​support
    • show_​source
    • sleep
    • sys_​getloadavg
    • time_​nanosleep
    • time_​sleep_​until
    • uniqid
    • unpack
    • usleep
To Top ↑ and ↓ to navigate • Enter to select • Esc to close • / to open Press Enter without selection to search using Google

Từ khóa » Hàm Eval Php