note 34273 added to language.operators.execution

From: Date: Sun, 20 Jul 2003 21:45:20 +0000
Subject: note 34273 added to language.operators.execution
Groups: php.notes 
Request: Send a blank email to php-notes+get-52428@lists.php.net to get a copy of this message
waylanator's example can be dangerous, since it doesn't prevent characters with special meaning from being emitted to the commandline. Programming errors or untrusted data could cause serious problems. At the bare minimum, remove all non-alphanumeric characters before passing a string to the shell. escapeshellarg() is also useful in *nix environments, but usually the best approach is to bypass the shell, using exec() etc. ---- Manual Page -- http://www.php.net/manual/en/language.operators.execution.php Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+34273 Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+34273&report=yes Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+34273&report=yes

« previous php.notes (#52428) next »