Doc #60116 [Fbk]: escapeshellcmd() cannot escape the chars which causes shell injection.
| From: | tyrael@php.net | Date: | Mon, 14 Nov 2011 09:50:59 +0000 |
| Subject: | Doc #60116 [Fbk]: escapeshellcmd() cannot escape the chars which causes shell injection. | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-7430@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=60116&edit=1
ID: 60116
Updated by: tyrael@php.net
Reported by: hirokawa@php.net
Summary: escapeshellcmd() cannot escape the chars which
causes shell injection.
Status: Feedback
Type: Documentation Problem
Package: Filter related
Operating System: Ubuntu Linux
PHP Version: trunk-SVN-2011-10-23 (SVN)
-Assigned To: lbarnaud
+Assigned To: tyrael
Block user comment: N
Private report: N
New Comment:
Arnaud, I will fix the docs, thanks for pointing out the problem.
Previous Comments:
------------------------------------------------------------------------
[2011-11-12 13:11:53] lbarnaud@php.net
@hirokawa you've assigned the bug to me, but I don't feel confident enough about my
english to update the docs myself.
The example could be something like this:
<?php
$e = escapeshellcmd($userinput);
system("echo $e");
?>
And a warning may be added:
The returned string may be interpreted as multiple arguments by the shell. Use escapeshellarg() for
escaping arguments.
------------------------------------------------------------------------
[2011-11-12 12:09:49] hirokawa@php.net
>the documentation should be updated (removing the flawed example, and
>emphasizing the correct usage).
Please do by yourself if you have the karma for phpdoc.
(I already removed the sentence which I added for the patch.)
If you don't have the karma, I will update the document.
And, you need to show a typical example of escapeshellcmd()
instead of the 'flawed' example you mentioned.
------------------------------------------------------------------------
[2011-11-11 15:19:51] tyrael@php.net
the documentation should be updated (removing the flawed example, and emphasizing
the correct usage).
------------------------------------------------------------------------
[2011-11-11 15:06:10] hirokawa@php.net
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
------------------------------------------------------------------------
[2011-11-11 14:52:48] hirokawa@php.net
Automatic comment from SVN on behalf of hirokawa
Revision: http://svn.php.net/viewvc/?view=revision&revision=319057
Log: revert changes to fix bug #60116.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=60116
--
Edit this bug report at https://bugs.php.net/bug.php?id=60116&edit=1