Re: Bug #3519: EscapeShellCmd is never useful

From: Date: Thu, 17 Feb 2000 17:42:56 +0000
Subject: Re: Bug #3519: EscapeShellCmd is never useful
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-15645@lists.php.net to get a copy of this message
Rasmus Lerdorf <rasmus@php.net> wrote: > What are you talking about? EscapeShellCmd() escapes *all* the problem > characters. Yours only escapes one. Apart from that they do the same > thing. No they don't. My version escapes all characters perfectly well. Within single quotes, no characters need escaping except single quotes. The difference is that EscapeShellCmd is designed to be called on an entire string to be passed to the shell, which is no use to anyone, since it means it has no way of telling which shell meta-characters you really want, and which ones are evil. My new suggested function is designed to be called on a single argument to a shell command line, and causes that single argument to be definitely interepreted as a single argument to a command, and nothing else. As an example, if you use the existing EscapeShellCmd function on a string, and the user-supplied input has a space character in it, then you end up with the user-supplied input being parsed as two arguments instead of one. See my example in the bug report for an example of the correct way to pass user input to a shell command line. Cheers Jon -- \/ Jon Ribbens / jon@oaktree.co.uk

« previous php.dev (#15645) next »