Re: CGI
| From: | Simon Willison | Date: | Tue, 26 Feb 2002 16:08:33 +0000 |
| Subject: | Re: CGI | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-86265@lists.php.net to get a copy of this message | ||
bvr wrote:
Still this wouldn't prevent a visitor from passing something like : ../../../../bin/cat /etc/passwd bvr. Erk good point - I should have mentioned that it's a very good idea to run basename() on user input as well as this will knock off any directory paths they may have attempted to add. Alternatively run a regular expression so ensure their input consists only of harmless characters (for example[a-zA-Z0-9] )http://www.php.net/basename
if (action=="cgi") echoIf you still want to use that method have a look at these two functions which can be used to make user input "safe" for use on a command line: http://www.php.net/manual/en/function.escapeshellarg.php http://www.php.net/manual/en/function.escapeshellcmd.php Simon./cgi-bin/cgiscripts/${scripts} 2&>1;