Re: Bug #3519: EscapeShellCmd is never useful
| From: | Rasmus Lerdorf | Date: | Thu, 17 Feb 2000 17:36:04 +0000 |
| Subject: | Re: Bug #3519: EscapeShellCmd is never useful | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-15643@lists.php.net to get a copy of this message | ||
What are you talking about? EscapeShellCmd() escapes *all* the problem
characters. Yours only escapes one. Apart from that they do the same
thing.
On 17 Feb 2000 jon@oaktree.co.uk wrote:
> From: jon@oaktree.co.uk
> Operating system: Unix
> PHP version: 3.0.11
> PHP Bug Type: Misbehaving function
> Bug description: EscapeShellCmd is never useful
>
> The EscapeShellCmd is not useful. What are you supposed to do with it? It's pointless.
>
> You should instead have a new function, EscapeShellArg, which does the following:
>
> function EscapeShellArg($cmd) {
> return "'".ereg_replace("'", "'\\''",
> $cmd)."'";
> }
>
> this way you actually *can* run shell processes safely, e.g.:
>
> exec('/bin/foo arg1 arg2 '.EscapeShellArg($cgivar));
>
>
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>