Re: Bug #11890 Updated: linux exploitable
| From: | derick@php.net | Date: | Thu, 05 Jul 2001 08:15:30 +0000 |
| Subject: | Re: Bug #11890 Updated: linux exploitable | ||
| References: | 1 | Groups: | php.dev php.dev php.dev |
| Request: | Send a blank email to php-dev+get-59299@lists.php.net to get a copy of this message | ||
On Thu, 5 Jul 2001, Zak Greant wrote:
> _shell_arg single quotes a string, and converts any existing
> single quotes (') in the value are to '\''. This sequence
> temporarily ends the single-quoted string, inserts a literal
> single quote, and then resumes the string.
>
> Shells don't interpret *anything* inside of a single quoted
> string, making this a very safe strategy (IMUO)
Ah you're right about that. I just saw the escaping of ' in the string,
but not the quoting. I've a fix ready now. Will commit after I tested it a
little more.
regards,
Derick Rethans
---------------------------------------------------------------------
PHP: Scripting the Web - www.php.net - derick@php.net
SRM: Site Resource Manager - www.vl-srm.net
---------------------------------------------------------------------