note 24132 deleted from function.escapeshellarg by didou
| From: | didou@php.net | Date: | Sun, 18 May 2003 04:43:58 +0000 |
| Subject: | note 24132 deleted from function.escapeshellarg by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-48425@lists.php.net to get a copy of this message | ||
Note Submitter:
----
I am somewhat confused. If I do this (as noted above):
$newstring = escapeshellarg("foo'bar");
Then $newstring becomes 'foo'\''bar'. This is totally unusable for shell
arguments. What I expected as the result would be "escape any single quotes in the string, then
put single quotes around the entire string only", yielding 'foo\'bar'.
My solution is:
$newstring = "'" . ereg_replace("'", "\\'",
"foo'bar") . "'";
Please note that this still leaves semicolons and other dangerous characters unquoted, as
escapeshellarg() does.
This looks like a complete solution for escaping shell arguments to me:
$dangerous = "foo'bar; rm -fr /*";
$newstring = "'" . escapeshellcmd($dangerous) . "'";
It escapes dangerous characters, then puts single quotes around the entire string, so that strings
(arguments) with spaces in them work correctly.