Doc #60116 [Fbk]: escapeshellcmd() cannot escape the chars which causes shell injection.

From: Date: Mon, 14 Nov 2011 09:50:59 +0000
Subject: Doc #60116 [Fbk]: escapeshellcmd() cannot escape the chars which causes shell injection.
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-7430@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=60116&edit=1 ID: 60116 Updated by: tyrael@php.net Reported by: hirokawa@php.net Summary: escapeshellcmd() cannot escape the chars which causes shell injection. Status: Feedback Type: Documentation Problem Package: Filter related Operating System: Ubuntu Linux PHP Version: trunk-SVN-2011-10-23 (SVN) -Assigned To: lbarnaud +Assigned To: tyrael Block user comment: N Private report: N New Comment: Arnaud, I will fix the docs, thanks for pointing out the problem. Previous Comments: ------------------------------------------------------------------------ [2011-11-12 13:11:53] lbarnaud@php.net @hirokawa you've assigned the bug to me, but I don't feel confident enough about my english to update the docs myself. The example could be something like this: <?php $e = escapeshellcmd($userinput); system("echo $e"); ?> And a warning may be added: The returned string may be interpreted as multiple arguments by the shell. Use escapeshellarg() for escaping arguments. ------------------------------------------------------------------------ [2011-11-12 12:09:49] hirokawa@php.net >the documentation should be updated (removing the flawed example, and >emphasizing the correct usage). Please do by yourself if you have the karma for phpdoc. (I already removed the sentence which I added for the patch.) If you don't have the karma, I will update the document. And, you need to show a typical example of escapeshellcmd() instead of the 'flawed' example you mentioned. ------------------------------------------------------------------------ [2011-11-11 15:19:51] tyrael@php.net the documentation should be updated (removing the flawed example, and emphasizing the correct usage). ------------------------------------------------------------------------ [2011-11-11 15:06:10] hirokawa@php.net Thank you for taking the time to write to us, but this is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php ------------------------------------------------------------------------ [2011-11-11 14:52:48] hirokawa@php.net Automatic comment from SVN on behalf of hirokawa Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=319057 Log: revert changes to fix bug #60116. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=60116 -- Edit this bug report at https://bugs.php.net/bug.php?id=60116&edit=1

« previous php.doc.bugs (#7430) next »