Re: Bug #3519: EscapeShellCmd is never useful
| From: | Jon Ribbens | Date: | Thu, 17 Feb 2000 18:19:48 +0000 |
| Subject: | Re: Bug #3519: EscapeShellCmd is never useful | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-15649@lists.php.net to get a copy of this message | ||
Rasmus Lerdorf <rasmus@php.net> wrote:
> Without the escape, this simple little exploit would work, with it, it
> doesn't. So I am not sure how you can say that the function is never
> useful. If you want users to be allowed to enter spaces and other chars
> and have it be treated as a single arg you could do:
>
> system("cal 2000 '$a'");
Uh-uh. No cigar. The user might put a "'" in their input, in which case
they can escape from the single quotes in your example. ("'" becomes
"\'",
but "\" is not special inside single quotes so is not effective.)
system('cal 2000 "'.$a.'"') might work but I can't tell because
what
EscapeShellCmd actually does is mostly undocumented.
I think there is a great need at least for the documentation to be improved
so that it is defined what guarantees EscapeShellCmd gives you (preferably
with a specification of what it does), and with some examples of its
correct usage.
But the simplest thing to do, which is easy to document, and is most
likely to be correct, is to implement the new function as I described.
Cheers
Jon
--
\/ Jon Ribbens / jon@oaktree.co.uk