note 9528 deleted from function.popen by vincent
| From: | vincent@php.net | Date: | Sat, 16 Aug 2003 15:30:15 +0000 |
| Subject: | note 9528 deleted from function.popen by vincent | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-54388@lists.php.net to get a copy of this message | ||
Note Submitter: jwilkins@bitland.net
----
Be _CAREFUL_ with this one.. popen() is potentially really bad from a security standpoint.. if you
allow any parameter to be passed in from user input, then it is possible for the user to execute
arbitrary commands as the account that the webserver is running as.
for an example, check http://www.bitland.net/article.php?sid=1&mode=thread&order=0