note 25203 deleted from function.escapeshellarg by didou

From: Date: Sun, 18 May 2003 04:44:53 +0000
Subject: note 25203 deleted from function.escapeshellarg by didou
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-48427@lists.php.net to get a copy of this message
Note Submitter: akubra ---- This function is doing exactly what is noted in it's description - making single safe argument which can be passed to shell function. Note that solution suggested above: $newstring = "'" . ereg_replace("'", "\\'", "foo'bar") . "'"; is wrong. Variable $newstring will have value 'foo\'bar' which is everything but not valid shell argument. Try ls -l 'foo\'bar' and you will get nothing. On the other side escapeshellarg("foo'bar") will return 'foo'\''bar', and ls -l 'foo'\''bar' will give what you expect. If you need to pass some input to external program and store it's output in variable, combination of escapeshellarg and backtick operator will do the trick. For example, if you for some reason can't use iconv() function from PHP, you can use iconv from shell like this: // string with single quotes, spaces and bad things in it... $string="I'm going to be converted: é á ú ó ;/bin/cat /etc/passwd"; // make it safe, pipe to program and get result in variable $safe=escapeshellarg($string); $converted=/bin/echo $safe | /usr/bin/iconv -f iso-8859-1 -t utf8;

« previous php.notes (#48427) next »