note 25203 added to function.escapeshellarg
| From: | akubra at rack1 dot php dot net | Date: | Fri, 13 Sep 2002 23:53:15 +0000 |
| Subject: | note 25203 added to function.escapeshellarg | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-36658@lists.php.net to get a copy of this message | ||
This function is doing exactly what is noted in it's description - making single safe argument
which can be passed to shell function. Note that solution suggested above:
$newstring = "'" . ereg_replace("'", "\\'",
"foo'bar") . "'";
is wrong. Variable $newstring will have value 'foo\'bar' which is everything but not
valid shell argument. Try ls -l 'foo\'bar' and you will get nothing. On the other
side escapeshellarg("foo'bar") will return 'foo'\''bar', and
ls -l 'foo'\''bar' will give what you expect.
If you need to pass some input to external program and store it's output in variable,
combination of escapeshellarg and backtick operator will do the trick. For example, if you for some
reason can't use iconv() function from PHP, you can use iconv from shell like this:
// string with single quotes, spaces and bad things in it...
$string="I'm going to be converted: é á ú ó ;/bin/cat /etc/passwd";
// make it safe, pipe to program and get result in variable
$safe=escapeshellarg($string);
$converted=
/bin/echo $safe | /usr/bin/iconv -f iso-8859-1 -t utf8;
--
http://www.php.net/manual/en/function.escapeshellarg.php
http://master.php.net/manage/user-notes.php?action=edit+25203
http://master.php.net/manage/user-notes.php?action=delete+25203
http://master.php.net/manage/user-notes.php?action=reject+25203