Bug #3519: EscapeShellCmd is never useful
| From: | jon at oaktree dot co dot uk | Date: | Thu, 17 Feb 2000 15:13:26 +0000 |
| Subject: | Bug #3519: EscapeShellCmd is never useful | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-15634@lists.php.net to get a copy of this message | ||
From: jon@oaktree.co.uk
Operating system: Unix
PHP version: 3.0.11
PHP Bug Type: Misbehaving function
Bug description: EscapeShellCmd is never useful
The EscapeShellCmd is not useful. What are you supposed to do with it? It's pointless.
You should instead have a new function, EscapeShellArg, which does the following:
function EscapeShellArg($cmd) {
return "'".ereg_replace("'", "'\\''",
$cmd)."'";
}
this way you actually *can* run shell processes safely, e.g.:
exec('/bin/foo arg1 arg2 '.EscapeShellArg($cgivar));