Doc #60116 [Fbk->Csd]: escapeshellcmd() cannot escape the chars which causes shell injection.

From: Date: Sat, 19 Nov 2011 23:48:23 +0000
Subject: Doc #60116 [Fbk->Csd]: escapeshellcmd() cannot escape the chars which causes shell injection.
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-7451@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=60116&edit=1 ID: 60116 Updated by: tyrael@php.net Reported by: hirokawa@php.net Summary: escapeshellcmd() cannot escape the chars which causes shell injection. -Status: Feedback +Status: Closed Type: Documentation Problem Package: Filter related Operating System: Ubuntu Linux PHP Version: trunk-SVN-2011-10-23 (SVN) Assigned To: tyrael Block user comment: N Private report: N New Comment: This bug has been fixed in SVN. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. I updated the documentation that reflect that: - escapeshellcmd should be used only on the full command - it will only prevent executing arbitrary commands, but still allow argument injection. - for escaping an argument, escapeshellarg should be used I didn't mentioned the quoting, because escapeshellarg already describe that the argument will be quoted, and as I mentioned, escapeshellcmd should only be used with a full command, so the quoting shouldn't be ambiguous there. http://svn.php.net/viewvc?view=revision&revision=319565 Previous Comments: ------------------------------------------------------------------------ [2011-11-19 23:04:31] tyrael@php.net Automatic comment from SVN on behalf of tyrael Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=319565 Log: fixing #60116 ------------------------------------------------------------------------ [2011-11-14 09:50:59] tyrael@php.net Arnaud, I will fix the docs, thanks for pointing out the problem. ------------------------------------------------------------------------ [2011-11-12 13:11:53] lbarnaud@php.net @hirokawa you've assigned the bug to me, but I don't feel confident enough about my english to update the docs myself. The example could be something like this: <?php $e = escapeshellcmd($userinput); system("echo $e"); ?> And a warning may be added: The returned string may be interpreted as multiple arguments by the shell. Use escapeshellarg() for escaping arguments. ------------------------------------------------------------------------ [2011-11-12 12:09:49] hirokawa@php.net >the documentation should be updated (removing the flawed example, and >emphasizing the correct usage). Please do by yourself if you have the karma for phpdoc. (I already removed the sentence which I added for the patch.) If you don't have the karma, I will update the document. And, you need to show a typical example of escapeshellcmd() instead of the 'flawed' example you mentioned. ------------------------------------------------------------------------ [2011-11-11 15:19:51] tyrael@php.net the documentation should be updated (removing the flawed example, and emphasizing the correct usage). ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=60116 -- Edit this bug report at https://bugs.php.net/bug.php?id=60116&edit=1

« previous php.doc.bugs (#7451) next »