note 24132 added to function.escapeshellarg

From: Date: Wed, 07 Aug 2002 15:00:14 +0000
Subject: note 24132 added to function.escapeshellarg
Groups: php.notes 
Request: Send a blank email to php-notes+get-34458@lists.php.net to get a copy of this message
I am somewhat confused. If I do this (as noted above): $newstring = escapeshellarg("foo'bar"); Then $newstring becomes 'foo'\''bar'. This is totally unusable for shell arguments. What I expected as the result would be "escape any single quotes in the string, then put single quotes around the entire string only", yielding 'foo\'bar'. My solution is: $newstring = "'" . ereg_replace("'", "\\'", "foo'bar") . "'"; Please note that this still leaves semicolons and other dangerous characters unquoted, as escapeshellarg() does. This looks like a complete solution for escaping shell arguments to me: $dangerous = "foo'bar; rm -fr /*"; $newstring = "'" . escapeshellcmd($dangerous) . "'"; It escapes dangerous characters, then puts single quotes around the entire string, so that strings (arguments) with spaces in them work correctly. -- http://www.php.net/manual/en/function.escapeshellarg.php http://master.php.net/manage/user-notes.php?action=edit+24132 http://master.php.net/manage/user-notes.php?action=delete+24132 http://master.php.net/manage/user-notes.php?action=reject+24132

« previous php.notes (#34458) next »