php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #60269 escapeshellcmd example is wrong; and warning should be added
Submitted: 2011-11-11 16:08 UTC Modified: 2011-12-03 06:40 UTC
From: lbarnaud@php.net Assigned: tyrael (profile)
Status: Closed Package: Documentation problem
PHP Version: Irrelevant OS:
Private report: No CVE-ID: None
 [2011-11-11 16:08 UTC] lbarnaud@php.net
Description:
------------
The example on http://docs.php.net/escapeshellcmd is wrong:

<?php
// here we don't care if $e has spaces
system("echo $e");
$f = escapeshellcmd($filename);
 
// and here we do, so we use quotes
system("touch \"/tmp/$f\"; ls -l \"/tmp/$f\"");
?>

- Escapeshellcmd is meant to be used without quotes
- Adding quotes around an escaped string doesn't prevent it from being interpreted as multiple arguments by the shell:

printf('touch "/tmp/%s"', escapeshellcmd('foo" "bar'));

Result:

touch "/tmp/foo" "bar" // two arguments

The correct way of escaping an argument is to use escapeshellarg():

printf('touch /tmp/%s', escapeshellarg('foo" "bar'));

Result:

touch /tmp/'foo" "bar' // one argument

I think the second part of the example should be removed, and a warning should be added:

The string may be interpreted as multiple arguments, use escapeshellarg instead.


Related reports: https://bugs.php.net/bug.php?id=47694


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2011-12-03 06:40 UTC] frozenfire@php.net
-Status: Open +Status: Closed -Assigned To: +Assigned To: tyrael
 [2011-12-03 06:40 UTC] frozenfire@php.net
Tyrael fixed this bug while closing bug #60116.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 19:00:01 2026 UTC