note 34273 added to language.operators.execution
| From: | aaron dot bentley at utoronto dot ca | Date: | Sun, 20 Jul 2003 21:45:20 +0000 |
| Subject: | note 34273 added to language.operators.execution | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-52428@lists.php.net to get a copy of this message | ||
waylanator's example can be dangerous, since it doesn't prevent characters with special
meaning from being emitted to the commandline. Programming errors or untrusted data could cause
serious problems. At the bare minimum, remove all non-alphanumeric characters before passing a
string to the shell. escapeshellarg() is also useful in *nix environments, but usually the best
approach is to bypass the shell, using exec() etc.
----
Manual Page -- http://www.php.net/manual/en/language.operators.execution.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+34273
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+34273&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+34273&report=yes