Re: Bug #3519: EscapeShellCmd is never useful

From: Date: Thu, 17 Feb 2000 18:24:39 +0000
Subject: Re: Bug #3519: EscapeShellCmd is never useful
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-15651@lists.php.net to get a copy of this message
> Rasmus Lerdorf <rasmus@php.net> wrote: > > Without the escape, this simple little exploit would work, with it, it > > doesn't. So I am not sure how you can say that the function is never > > useful. If you want users to be allowed to enter spaces and other chars > > and have it be treated as a single arg you could do: > > > > system("cal 2000 '$a'"); > > Uh-uh. No cigar. The user might put a "'" in their input, in which case > they can escape from the single quotes in your example. ("'" becomes > "\'", > but "\" is not special inside single quotes so is not effective.) If the user input is: 2';ls The full command ends up being: cal 2000 '2\'\;ls' That's perfectly fine and doesn't make the 'ls' execute. -Rasmus

« previous php.dev (#15651) next »