Re: CGI
| From: | Simon Willison | Date: | Tue, 26 Feb 2002 15:14:21 +0000 |
| Subject: | Re: CGI | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-86252@lists.php.net to get a copy of this message | ||
bvr wrote:
Please note that plain this:http://www.php.net/manual/en/function.escapeshellarg.php http://www.php.net/manual/en/function.escapeshellcmd.php Simonor <? if (action=="cgi") echois not a good idea, because it allows a visitor to run arbitrary commands on your server. bvr. If you still want to use that method have a look at these two functions which can be used to make user input "safe" for use on a command line:./cgi-bin/cgiscripts/${scripts} 2&>1; ?>