<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<meta content="text/html;charset=ISO-8859-1" http-equiv="Content-Type">
<title></title>
</head>
<body bgcolor="#ffffff" text="#000000">
Emiliano Gabrielli (aka AlberT) ha scritto:
<blockquote cite="mid200705071113.37375.AlberT@superalbert.it"
type="cite">
<pre wrap="">On lunedì 7 maggio 2007, Alessandro Marinuzzi wrote:
</pre>
<blockquote type="cite">
<pre wrap="">Va bene questa regex secondo voi?
</pre>
</blockquote>
<pre wrap=""><!---->
eval ('mio codice')
</pre>
</blockquote>
Che vuoi dire che non va bene?<br>
<br>
<a class="moz-txt-link-freetext" href="http://secunia.com/advisories/23604/">http://secunia.com/advisories/23604/</a><br>
<a class="moz-txt-link-freetext" href="http://secunia.com/advisories/24374/">http://secunia.com/advisories/24374/</a><br>
<a class="moz-txt-link-freetext" href="http://www.owasp.org/index.php/Direct_Dynamic_Code_Evaluation_(">http://www.owasp.org/index.php/Direct_Dynamic_Code_Evaluation_(</a>'Eval_Injection')<br>
<a class="moz-txt-link-freetext" href="http://en.wikipedia.org/wiki/Code_injection">http://en.wikipedia.org/wiki/Code_injection</a><br>
<a class="moz-txt-link-freetext" href="http://php.html.it/articoli/stampa/1936/scrivere-applicazioni-php-sicure/">http://php.html.it/articoli/stampa/1936/scrivere-applicazioni-php-sicure/</a><br>
<br>
e cercando bene in rete se ne trovano ancora ;-(<br>
<br>
<pre class="moz-signature" cols="76">--
Alessandro Marinuzzi
--------------------
<a class="moz-txt-link-freetext" href="http://www.alecos.it">http://www.alecos.it</a>
--------------------</pre>
</body>
</html>