note 58680 added to function.escapeshellarg
| From: | phpnet at lostreality dot org | Date: | Fri, 11 Nov 2005 16:53:13 +0000 |
| Subject: | note 58680 added to function.escapeshellarg | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-98436@lists.php.net to get a copy of this message | ||
This function does not escape $ it seems. This lets user embed shell variables such as $PATH into
commands, which you may or may not want to allow. I'm using shell_exec() because I need the
entire command as one string, and need access to the stdout data as one string as well.
----
Manual Page -- http://www.php.net/manual/en/function.escapeshellarg.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+58680
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+58680&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+58680&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+58680&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+58680&report=yes&reason=useless
Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+58680&report=yes&reason=non-english
Delete: already in docs -- http://master.php.net/manage/user-notes.php?action=delete+58680&report=yes&reason=already+in+docs
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+58680&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+58680&report=yes
Search -- http://master.php.net/manage/user-notes.php