Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Tue, 05 Sep 2000 14:55:45 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-32187@lists.php.net to get a copy of this message
Rasmus Lerdorf <rasmus@php.net> wrote: > > > system("ls $a $b"); > > > > As I said at the time, this is broken. Try '$a = "a b"' and see what > > you > > get. > > You get: ls a b > > This does not let anybody escape out of the shell command. Not with 'ls' it doesn't, no. But it means that the shell command is not receiving what you intended, i.e. a single parameter. With some shell commands this will be *important* and may well involve a security problem.

« previous php.dev (#32187) next »