note 34273 deleted from language.operators.execution by salathe
| From: | salathe@php.net | Date: | Tue, 08 Oct 2019 18:30:16 +0000 |
| Subject: | note 34273 deleted from language.operators.execution by salathe | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-212555@lists.php.net to get a copy of this message | ||
Note Submitter: aaron dot bentley at utoronto dot ca
----
waylanator's example can be dangerous, since it doesn't prevent characters with special
meaning from being emitted to the commandline. Programming errors or untrusted data could cause
serious problems. At the bare minimum, remove all non-alphanumeric characters before passing a
string to the shell. escapeshellarg() is also useful in *nix environments, but usually the best
approach is to bypass the shell, using exec() etc.