Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Tue, 05 Sep 2000 15:09:43 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32192@lists.php.net to get a copy of this message | ||
Rasmus Lerdorf <rasmus@php.net> wrote:
> > Not with 'ls' it doesn't, no. But it means that the shell command is not
> > receiving what you intended, i.e. a single parameter. With some shell
> > commands this will be *important* and may well involve a security
> > problem.
>
> But is it EscapeShellCmd()'s job to ensure a string is a single
> parameter?
If it isn't, whose job is it?
If you want to pass an argument to a shell command, as simply as that, then
EscapeShellCmd can't do it, and there isn't a built-in function that can.
So, what use is EscapeShellCmd?