Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Tue, 05 Sep 2000 14:33:38 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32180@lists.php.net to get a copy of this message | ||
Rasmus Lerdorf <rasmus@php.net> wrote:
> It was a usage difference. You said the function was completely
> useless. I said it was quite useful the way I have always used it. ie.
>
> $a = "a;b";
> $b = "c;d";
> $a = escapeshellcmd($a);
> $b = escapeshellcmd($b);
> system("ls $a $b");
As I said at the time, this is broken. Try '$a = "a b"' and see what you get.
> But regardless, I'm not the one blocking anything. There are dozens of
> people who read php-dev with cvs commit access and you didn't manage to
> convince any of them to commit your code.
I didn't see any evidence of any one else paying any attention at all.