Re: CGI

From: Date: Tue, 26 Feb 2002 15:24:42 +0000
Subject: Re: CGI
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-86254@lists.php.net to get a copy of this message
Still this wouldn't prevent a visitor from passing something like : ../../../../bin/cat /etc/passwd bvr. >>if (action=="cgi") echo ./cgi-bin/cgiscripts/${scripts} >>2&>1; > >If you still want to use that method have a look at these two functions >which can be used to make user input "safe" for use on a command line: > >http://www.php.net/manual/en/function.escapeshellarg.php >http://www.php.net/manual/en/function.escapeshellcmd.php > >Simon

« previous php.general (#86254) next »