Re: Bug #3519: EscapeShellCmd is never useful

From: Date: Thu, 17 Feb 2000 18:19:48 +0000
Subject: Re: Bug #3519: EscapeShellCmd is never useful
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-15649@lists.php.net to get a copy of this message
Rasmus Lerdorf <rasmus@php.net> wrote: > Without the escape, this simple little exploit would work, with it, it > doesn't. So I am not sure how you can say that the function is never > useful. If you want users to be allowed to enter spaces and other chars > and have it be treated as a single arg you could do: > > system("cal 2000 '$a'"); Uh-uh. No cigar. The user might put a "'" in their input, in which case they can escape from the single quotes in your example. ("'" becomes "\'", but "\" is not special inside single quotes so is not effective.) system('cal 2000 "'.$a.'"') might work but I can't tell because what EscapeShellCmd actually does is mostly undocumented. I think there is a great need at least for the documentation to be improved so that it is defined what guarantees EscapeShellCmd gives you (preferably with a specification of what it does), and with some examples of its correct usage. But the simplest thing to do, which is easy to document, and is most likely to be correct, is to implement the new function as I described. Cheers Jon -- \/ Jon Ribbens / jon@oaktree.co.uk

« previous php.dev (#15649) next »