note 24132 deleted from function.escapeshellarg by didou

From: Date: Sun, 18 May 2003 04:43:58 +0000
Subject: note 24132 deleted from function.escapeshellarg by didou
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-48425@lists.php.net to get a copy of this message
Note Submitter: ---- I am somewhat confused. If I do this (as noted above): $newstring = escapeshellarg("foo'bar"); Then $newstring becomes 'foo'\''bar'. This is totally unusable for shell arguments. What I expected as the result would be "escape any single quotes in the string, then put single quotes around the entire string only", yielding 'foo\'bar'. My solution is: $newstring = "'" . ereg_replace("'", "\\'", "foo'bar") . "'"; Please note that this still leaves semicolons and other dangerous characters unquoted, as escapeshellarg() does. This looks like a complete solution for escaping shell arguments to me: $dangerous = "foo'bar; rm -fr /*"; $newstring = "'" . escapeshellcmd($dangerous) . "'"; It escapes dangerous characters, then puts single quotes around the entire string, so that strings (arguments) with spaces in them work correctly.

« previous php.notes (#48425) next »