Re: CGI

From: Date: Tue, 26 Feb 2002 16:08:33 +0000
Subject: Re: CGI
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-86265@lists.php.net to get a copy of this message
bvr wrote:
Still this wouldn't prevent a visitor from passing something like : ../../../../bin/cat /etc/passwd bvr. Erk good point - I should have mentioned that it's a very good idea to run basename() on user input as well as this will knock off any directory paths they may have attempted to add. Alternatively run a regular expression so ensure their input consists only of harmless characters (for example[a-zA-Z0-9] )
http://www.php.net/basename
if (action=="cgi") echo ./cgi-bin/cgiscripts/${scripts} 2&>1;
If you still want to use that method have a look at these two functions which can be used to make user input "safe" for use on a command line: http://www.php.net/manual/en/function.escapeshellarg.php http://www.php.net/manual/en/function.escapeshellcmd.php Simon


« previous php.general (#86265) next »