PDA

View Full Version : 通过eval()函数可以实现字符串当php代码来执行


New Monmouth
2014-11-27, 01:34 PM
$tmp = "phpinfo();";
eval_r($tmp);

Newald
2014-11-27, 02:04 PM
<?php
$string = "phpinfo();";


eval("$string");

?>