Re: Bug #3519: EscapeShellCmd is never useful
| From: | Jon Ribbens | Date: | Thu, 17 Feb 2000 17:42:56 +0000 |
| Subject: | Re: Bug #3519: EscapeShellCmd is never useful | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-15645@lists.php.net to get a copy of this message | ||
Rasmus Lerdorf <rasmus@php.net> wrote:
> What are you talking about? EscapeShellCmd() escapes *all* the problem
> characters. Yours only escapes one. Apart from that they do the same
> thing.
No they don't. My version escapes all characters perfectly well.
Within single quotes, no characters need escaping except single quotes.
The difference is that EscapeShellCmd is designed to be called on an
entire string to be passed to the shell, which is no use to anyone,
since it means it has no way of telling which shell meta-characters
you really want, and which ones are evil.
My new suggested function is designed to be called on a single argument
to a shell command line, and causes that single argument to be definitely
interepreted as a single argument to a command, and nothing else.
As an example, if you use the existing EscapeShellCmd function on a string,
and the user-supplied input has a space character in it, then you end up
with the user-supplied input being parsed as two arguments instead of one.
See my example in the bug report for an example of the correct way to
pass user input to a shell command line.
Cheers
Jon
--
\/ Jon Ribbens / jon@oaktree.co.uk