ZF-11715: Zend_Form_Element uses create_function() where a real function would suffice.

Issue Type: Bug Created: 2011-09-02T08:33:15.000+0000 Last Updated: 2011-09-02T14:17:27.000+0000 Status: Resolved Fix version(s): - 1.11.11 (29/Sep/11)

Reporter: Benjamin Eberlei (beberlei) Assignee: Matthew Weier O'Phinney (matthew) Tags: - Zend_Form

Related issues: Attachments:


I consider this a bug and critical, because create_function() is just another name for eval().

Zend_Form_Element::loadDefaultDecorators() uses create_function() as of trunk and 2.0, its not in 1.9. Please remove it.


Posted by Matthew Weier O'Phinney (matthew) on 2011-09-02T14:17:26.000+0000

Fixed in r24427 in trunk and r24428 in the 1.11 release branch, and d2db390 on ZF2 master.

Have you found an issue?

See the Overview section for more details.


© 2006-2018 by Zend, a Rogue Wave Company. Made with by awesome contributors.

This website is built using zend-expressive and it runs on PHP 7.