Re: Bug #11890 Updated: linux exploitable

From: Date: Wed, 04 Jul 2001 23:06:15 +0000
Subject: Re: Bug #11890 Updated: linux exploitable
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-58932@lists.php.net to get a copy of this message
Derick wrote: > Hello Zak, > > regarding this problem with the mail() function, I have a fix here where > the 5th parameter will be shell escaped (with php_shell_escape_cmd()). I > didn't commit it yet (because of ISP troubles), but if nobody thinks this > is a bad idea, I'll commit it tomorrow. Hey Derick, Excellent! :) Should we be using php_escape_shell_arg() instead of php_escape_shell_cmd()? As I understand it, php_escape_shell_arg() is the simpler and more robust of the two functions. --zak

« previous php.dev (#58932) next »