Re: CGI
| From: | bvr | Date: | Tue, 26 Feb 2002 15:24:42 +0000 |
| Subject: | Re: CGI | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-86254@lists.php.net to get a copy of this message | ||
Still this wouldn't prevent a visitor from passing something like :
../../../../bin/cat /etc/passwd
bvr.
>>if (action=="cgi") echo
./cgi-bin/cgiscripts/${scripts}
>>2&>1;
>
>If you still want to use that method have a look at these two functions
>which can be used to make user input "safe" for use on a command line:
>
>http://www.php.net/manual/en/function.escapeshellarg.php
>http://www.php.net/manual/en/function.escapeshellcmd.php
>
>Simon