Re: Bug #11890 Updated: linux exploitable

From: Date: Thu, 05 Jul 2001 08:15:30 +0000
Subject: Re: Bug #11890 Updated: linux exploitable
References: 1  Groups: php.dev php.dev php.dev 
Request: Send a blank email to php-dev+get-59299@lists.php.net to get a copy of this message
On Thu, 5 Jul 2001, Zak Greant wrote: > _shell_arg single quotes a string, and converts any existing > single quotes (') in the value are to '\''. This sequence > temporarily ends the single-quoted string, inserts a literal > single quote, and then resumes the string. > > Shells don't interpret *anything* inside of a single quoted > string, making this a very safe strategy (IMUO) Ah you're right about that. I just saw the escaping of ' in the string, but not the quoting. I've a fix ready now. Will commit after I tested it a little more. regards, Derick Rethans --------------------------------------------------------------------- PHP: Scripting the Web - www.php.net - derick@php.net SRM: Site Resource Manager - www.vl-srm.net ---------------------------------------------------------------------

« previous php.dev (#59299) next »