Re: Bug #3519: EscapeShellCmd is never useful

From: Date: Thu, 17 Feb 2000 17:36:04 +0000
Subject: Re: Bug #3519: EscapeShellCmd is never useful
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-15643@lists.php.net to get a copy of this message
What are you talking about? EscapeShellCmd() escapes *all* the problem characters. Yours only escapes one. Apart from that they do the same thing. On 17 Feb 2000 jon@oaktree.co.uk wrote: > From: jon@oaktree.co.uk > Operating system: Unix > PHP version: 3.0.11 > PHP Bug Type: Misbehaving function > Bug description: EscapeShellCmd is never useful > > The EscapeShellCmd is not useful. What are you supposed to do with it? It's pointless. > > You should instead have a new function, EscapeShellArg, which does the following: > > function EscapeShellArg($cmd) { > return "'".ereg_replace("'", "'\\''", > $cmd)."'"; > } > > this way you actually *can* run shell processes safely, e.g.: > > exec('/bin/foo arg1 arg2 '.EscapeShellArg($cgivar)); > > > > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.dev (#15643) next »