Doc #60269 [Opn->Csd]: escapeshellcmd example is wrong; and warning should be added
| From: | frozenfire@php.net | Date: | Sat, 03 Dec 2011 06:40:42 +0000 |
| Subject: | Doc #60269 [Opn->Csd]: escapeshellcmd example is wrong; and warning should be added | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-7512@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=60269&edit=1
ID: 60269
Updated by: frozenfire@php.net
Reported by: lbarnaud@php.net
Summary: escapeshellcmd example is wrong; and warning should
be added
-Status: Open
+Status: Closed
Type: Documentation Problem
Package: Documentation problem
PHP Version: Irrelevant
-Assigned To:
+Assigned To: tyrael
Block user comment: N
Private report: N
New Comment:
Tyrael fixed this bug while closing bug #60116.
Previous Comments:
------------------------------------------------------------------------
[2011-11-11 16:08:57] lbarnaud@php.net
Description:
------------
The example on http://docs.php.net/escapeshellcmd
is wrong:
<?php
// here we don't care if $e has spaces
system("echo $e");
$f = escapeshellcmd($filename);
// and here we do, so we use quotes
system("touch \"/tmp/$f\"; ls -l \"/tmp/$f\"");
?>
- Escapeshellcmd is meant to be used without quotes
- Adding quotes around an escaped string doesn't prevent it from being interpreted as multiple
arguments by the shell:
printf('touch "/tmp/%s"', escapeshellcmd('foo" "bar'));
Result:
touch "/tmp/foo" "bar" // two arguments
The correct way of escaping an argument is to use escapeshellarg():
printf('touch /tmp/%s', escapeshellarg('foo" "bar'));
Result:
touch /tmp/'foo" "bar' // one argument
I think the second part of the example should be removed, and a warning should be added:
The string may be interpreted as multiple arguments, use escapeshellarg instead.
Related reports: https://bugs.php.net/bug.php?id=47694
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=60269&edit=1