note 68589 added to function.shell-exec
| From: | doo_mangle_fusatby_mangle_udizzotnet at osu1 dot php dot net | Date: | Wed, 02 Aug 2006 19:00:41 +0000 |
| Subject: | note 68589 added to function.shell-exec | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-115491@lists.php.net to get a copy of this message | ||
If you're on a host that provides neither shell access nor a way to unzip uploaded archives,
you can use PHP to call the unzip utility with shell_exec() (provided they're not also running
in safe mode). Just make sure that PHP has write permission to the destination directory, or it
won't work.
Here's an example script that accomplishes this, which you're free to use if you so chose:
<?php
$passwd = 'censored';
$filename = 'archive.zip';
$options = '-o'; //Overwrite existing files by default; this is mostly to suppress
confirmations
$destDir = '';
if (isset ($_POST['password'])) {
if ($_POST['password'] == $passwd) {
if (isset ($_POST['filename'])) { $filename = escapeshellarg
($_POST['filename']); }
if (isset ($_POST['updateExisting'])) { $options .= "u"; } //use with care,
since a timezone mismatch may occur; see man unzip
if (isset ($_POST['destDir'])) { $destDir = ' -d '. escapeshellarg
($_POST['destDir']); }
echo "<pre>";
echo shell_exec ("unzip $options {$filename}{$destDir}");
echo "</pre>";
}
else {
outputPage ("Your password didn't check out, mon. Better try it again, eh?");
}
}
else { outputPage(); }
function outputPage ($errorMessage = '') {
echo <<<HTML
<html><head><title>Unzip password verification</title>
<style type="text/css">
td.left { text-align: right; }
td.right { text-align: left; }
div { color: red; border: 1px solid gray; padding: 4px; }
</style>
</head>
<body>
HTML;
if (!empty ($errorMessage)) { echo "\n<div>$errorMessage</div>\n"; }
echo <<<HTMLL
<h1>Super Duper File Unzipper</h1>
<form name="zipform" method="post" action="unzipper.php">
<table>
<tr>
<td class="left">Filename:</td>
<td class="right"><input type="text" name="filename"
size="50" maxlength="255" /></td>
</tr><tr>
<td class="left">Destination Directory:</td>
<td class="right"><input type="text" name="destdir"
size="50" maxlength="1000" /></td>
</tr><tr>
<td class="left">Password:</td>
<td class="right"><input type="password" name="password"
size="15" maxlength="30" /></td>
<tr>
<td colspan="2"><input type="checkbox"
name="updateExisting" />Update existing files</td>
</tr><tr>
<td class="right"><input type="reset" value="Reset"
/></td>
<td class="left"><input type="submit" value="Unzip it!"
/></td>
</tr>
</table>
</form>
</body>
</html>
HTMLL;
}
?>
----
Server IP: 64.71.164.2
Probable Submitter: 71.211.138.24
----
X-Spam-Status: No, hits=4.2 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER,
HTML_40_50,HTML_MESSAGE autolearn=no version=2.64
----
Manual Page -- http://www.php.net/manual/en/function.shell-exec.php
Edit -- https://master.php.net/note/edit/68589
Del: integrated -- https://master.php.net/note/delete/68589/integrated
Del: useless -- https://master.php.net/note/delete/68589/useless
Del: bad code -- https://master.php.net/note/delete/68589/bad+code
Del: spam -- https://master.php.net/note/delete/68589/spam
Del: non-english -- https://master.php.net/note/delete/68589/non-english
Del: in docs -- https://master.php.net/note/delete/68589/in+docs
Del: other reasons-- https://master.php.net/note/delete/68589
Reject -- https://master.php.net/note/reject/68589
Search -- https://master.php.net/manage/user-notes.php