Doc #60269 [NEW]: escapeshellcmd example is wrong; and warning should be added
| From: | lbarnaud@php.net | Date: | Fri, 11 Nov 2011 16:08:58 +0000 |
| Subject: | Doc #60269 [NEW]: escapeshellcmd example is wrong; and warning should be added | ||
| Groups: | php.doc.bugs | ||
| Request: | Send a blank email to doc-bugs+get-7418@lists.php.net to get a copy of this message | ||
From:
Operating system:
PHP version: Irrelevant
Package: Documentation problem
Bug Type: Documentation Problem
Bug description:escapeshellcmd example is wrong; and warning should be added
Description:
------------
The example on http://docs.php.net/escapeshellcmd
is wrong:
<?php
// here we don't care if $e has spaces
system("echo $e");
$f = escapeshellcmd($filename);
// and here we do, so we use quotes
system("touch \"/tmp/$f\"; ls -l \"/tmp/$f\"");
?>
- Escapeshellcmd is meant to be used without quotes
- Adding quotes around an escaped string doesn't prevent it from being
interpreted as multiple arguments by the shell:
printf('touch "/tmp/%s"', escapeshellcmd('foo" "bar'));
Result:
touch "/tmp/foo" "bar" // two arguments
The correct way of escaping an argument is to use escapeshellarg():
printf('touch /tmp/%s', escapeshellarg('foo" "bar'));
Result:
touch /tmp/'foo" "bar' // one argument
I think the second part of the example should be removed, and a warning
should be added:
The string may be interpreted as multiple arguments, use escapeshellarg
instead.
Related reports: https://bugs.php.net/bug.php?id=47694
--
Edit bug report at https://bugs.php.net/bug.php?id=60269&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=60269&r=trysnapshot54
Try a snapshot (PHP 5.3): https://bugs.php.net/fix.php?id=60269&r=trysnapshot53
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=60269&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=60269&r=fixed
Fixed in SVN and need be documented: https://bugs.php.net/fix.php?id=60269&r=needdocs
Fixed in release: https://bugs.php.net/fix.php?id=60269&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=60269&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=60269&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=60269&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=60269&r=support
Expected behavior: https://bugs.php.net/fix.php?id=60269&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=60269&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=60269&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=60269&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=60269&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=60269&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=60269&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=60269&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=60269&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=60269&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=60269&r=mysqlcfg