note 24132 added to function.escapeshellarg
| From: | php-general at lists dot php dot net | Date: | Wed, 07 Aug 2002 15:00:14 +0000 |
| Subject: | note 24132 added to function.escapeshellarg | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-34458@lists.php.net to get a copy of this message | ||
I am somewhat confused. If I do this (as noted above):
$newstring = escapeshellarg("foo'bar");
Then $newstring becomes 'foo'\''bar'. This is totally unusable for shell
arguments. What I expected as the result would be "escape any single quotes in the string, then
put single quotes around the entire string only", yielding 'foo\'bar'.
My solution is:
$newstring = "'" . ereg_replace("'", "\\'",
"foo'bar") . "'";
Please note that this still leaves semicolons and other dangerous characters unquoted, as
escapeshellarg() does.
This looks like a complete solution for escaping shell arguments to me:
$dangerous = "foo'bar; rm -fr /*";
$newstring = "'" . escapeshellcmd($dangerous) . "'";
It escapes dangerous characters, then puts single quotes around the entire string, so that strings
(arguments) with spaces in them work correctly.
--
http://www.php.net/manual/en/function.escapeshellarg.php
http://master.php.net/manage/user-notes.php?action=edit+24132
http://master.php.net/manage/user-notes.php?action=delete+24132
http://master.php.net/manage/user-notes.php?action=reject+24132