Re: CGI

From: Date: Tue, 26 Feb 2002 15:14:21 +0000
Subject: Re: CGI
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-86252@lists.php.net to get a copy of this message
bvr wrote:
Please note that plain this:
or <? if (action=="cgi") echo ./cgi-bin/cgiscripts/${scripts} 2&>1; ?>
is not a good idea, because it allows a visitor to run arbitrary commands on your server. bvr. If you still want to use that method have a look at these two functions which can be used to make user input "safe" for use on a command line:
http://www.php.net/manual/en/function.escapeshellarg.php http://www.php.net/manual/en/function.escapeshellcmd.php Simon

« previous php.general (#86252) next »