Re: Bug #11890 Updated: linux exploitable
| From: | Zak Greant | Date: | Wed, 04 Jul 2001 23:06:15 +0000 |
| Subject: | Re: Bug #11890 Updated: linux exploitable | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-58932@lists.php.net to get a copy of this message | ||
Derick wrote:
> Hello Zak,
>
> regarding this problem with the mail() function, I have a fix here where
> the 5th parameter will be shell escaped (with php_shell_escape_cmd()). I
> didn't commit it yet (because of ISP troubles), but if nobody thinks this
> is a bad idea, I'll commit it tomorrow.
Hey Derick,
Excellent! :)
Should we be using php_escape_shell_arg() instead of
php_escape_shell_cmd()?
As I understand it, php_escape_shell_arg() is the simpler and more
robust of the two functions.
--zak