Re: Bug #3519: EscapeShellCmd is never useful
| From: | Rasmus Lerdorf | Date: | Thu, 17 Feb 2000 18:24:39 +0000 |
| Subject: | Re: Bug #3519: EscapeShellCmd is never useful | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-15651@lists.php.net to get a copy of this message | ||
> Rasmus Lerdorf <rasmus@php.net> wrote:
> > Without the escape, this simple little exploit would work, with it, it
> > doesn't. So I am not sure how you can say that the function is never
> > useful. If you want users to be allowed to enter spaces and other chars
> > and have it be treated as a single arg you could do:
> >
> > system("cal 2000 '$a'");
>
> Uh-uh. No cigar. The user might put a "'" in their input, in which case
> they can escape from the single quotes in your example. ("'" becomes
> "\'",
> but "\" is not special inside single quotes so is not effective.)
If the user input is: 2';ls
The full command ends up being:
cal 2000 '2\'\;ls'
That's perfectly fine and doesn't make the 'ls' execute.
-Rasmus