RE: [PHP] CGI

From: Date: Tue, 26 Feb 2002 15:17:30 +0000
Subject: RE: [PHP] CGI
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-86253@lists.php.net to get a copy of this message
Also, make sure that if you run the script with user input that you validate the input... Input like '<username>; cat /etc/passwd' would be no fun at all -----Original Message----- From: Simon Willison [mailto:cs1spw@bath.ac.uk] Sent: Tuesday, February 26, 2002 7:14 AM To: bvr Cc: php-general Subject: Re: [PHP] CGI bvr wrote: >Please note that plain this: > >>or >><? >>if (action=="cgi") echo ./cgi-bin/cgiscripts/${scripts} >>2&>1; >>?> >> >is not a good idea, because it allows a visitor to run arbitrary >commands on your server. > >bvr. > If you still want to use that method have a look at these two functions which can be used to make user input "safe" for use on a command line: http://www.php.net/manual/en/function.escapeshellarg.php http://www.php.net/manual/en/function.escapeshellcmd.php Simon -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php

« previous php.general (#86253) next »