Doc #60116 [Fbk->Csd]: escapeshellcmd() cannot escape the chars which causes shell injection.
| From: | tyrael@php.net | Date: | Sat, 19 Nov 2011 23:48:23 +0000 |
| Subject: | Doc #60116 [Fbk->Csd]: escapeshellcmd() cannot escape the chars which causes shell injection. | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-7451@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=60116&edit=1
ID: 60116
Updated by: tyrael@php.net
Reported by: hirokawa@php.net
Summary: escapeshellcmd() cannot escape the chars which
causes shell injection.
-Status: Feedback
+Status: Closed
Type: Documentation Problem
Package: Filter related
Operating System: Ubuntu Linux
PHP Version: trunk-SVN-2011-10-23 (SVN)
Assigned To: tyrael
Block user comment: N
Private report: N
New Comment:
This bug has been fixed in SVN.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
I updated the documentation that reflect that:
- escapeshellcmd should be used only on the full command
- it will only prevent executing arbitrary commands, but still allow argument
injection.
- for escaping an argument, escapeshellarg should be used
I didn't mentioned the quoting, because escapeshellarg already describe that the
argument will be quoted, and as I mentioned, escapeshellcmd should only be used
with a full command, so the quoting shouldn't be ambiguous there.
http://svn.php.net/viewvc?view=revision&revision=319565
Previous Comments:
------------------------------------------------------------------------
[2011-11-19 23:04:31] tyrael@php.net
Automatic comment from SVN on behalf of tyrael
Revision: http://svn.php.net/viewvc/?view=revision&revision=319565
Log: fixing #60116
------------------------------------------------------------------------
[2011-11-14 09:50:59] tyrael@php.net
Arnaud, I will fix the docs, thanks for pointing out the problem.
------------------------------------------------------------------------
[2011-11-12 13:11:53] lbarnaud@php.net
@hirokawa you've assigned the bug to me, but I don't feel confident enough about my
english to update the docs myself.
The example could be something like this:
<?php
$e = escapeshellcmd($userinput);
system("echo $e");
?>
And a warning may be added:
The returned string may be interpreted as multiple arguments by the shell. Use escapeshellarg() for
escaping arguments.
------------------------------------------------------------------------
[2011-11-12 12:09:49] hirokawa@php.net
>the documentation should be updated (removing the flawed example, and
>emphasizing the correct usage).
Please do by yourself if you have the karma for phpdoc.
(I already removed the sentence which I added for the patch.)
If you don't have the karma, I will update the document.
And, you need to show a typical example of escapeshellcmd()
instead of the 'flawed' example you mentioned.
------------------------------------------------------------------------
[2011-11-11 15:19:51] tyrael@php.net
the documentation should be updated (removing the flawed example, and emphasizing
the correct usage).
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=60116
--
Edit this bug report at https://bugs.php.net/bug.php?id=60116&edit=1