Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Tue, 05 Sep 2000 15:09:43 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-32192@lists.php.net to get a copy of this message
Rasmus Lerdorf <rasmus@php.net> wrote: > > Not with 'ls' it doesn't, no. But it means that the shell command is not > > receiving what you intended, i.e. a single parameter. With some shell > > commands this will be *important* and may well involve a security > > problem. > > But is it EscapeShellCmd()'s job to ensure a string is a single > parameter? If it isn't, whose job is it? If you want to pass an argument to a shell command, as simply as that, then EscapeShellCmd can't do it, and there isn't a built-in function that can. So, what use is EscapeShellCmd?

« previous php.dev (#32192) next »