Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Wed, 06 Sep 2000 09:32:32 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32331@lists.php.net to get a copy of this message | ||
Rasmus Lerdorf <rasmus@php.net> wrote:
> Well, it is exactly like your AddSlashes() argument. You think AddSlashes
> should also add quotes.
There is no connection between these two points. Yes, I think addslashes()
would be better if it added quotes. I don't think it is broken because it
doesn't.
> Perhaps we should have AddSlashesAndQuotes() and EscapeShellArg(), and
> that is probably a good idea, but it does not make the existing functions
> useless as you like to keep saying.
I never said addslashes() was useless. I said EscapeShellCmd is useless.
We have already demonstrated in this thread that even you do not know
how to use it properly! How is the average PHP script programmer supposed
to cope? At the very least, its correct usage should be documented in the
manual. Preferably, it should be superceded by the safer and more useful
function I described, but that is an optional extra.
Cheers
Jon