Re: PHP File Upload Security Hole - Still No Fix?
| From: | Rasmus Lerdorf | Date: | Tue, 05 Sep 2000 15:07:17 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32190@lists.php.net to get a copy of this message | ||
> Rasmus Lerdorf <rasmus@php.net> wrote:
> > > > system("ls $a $b");
> > >
> > > As I said at the time, this is broken. Try '$a = "a b"' and see
> > > what you
> > > get.
> >
> > You get: ls a b
> >
> > This does not let anybody escape out of the shell command.
>
> Not with 'ls' it doesn't, no. But it means that the shell command is not
> receiving what you intended, i.e. a single parameter. With some shell
> commands this will be *important* and may well involve a security
> problem.
But is it EscapeShellCmd()'s job to ensure a string is a single
parameter?
-Rasmus