文章详情

  • 游戏榜单
  • 软件榜单
关闭导航
热搜榜
热门下载
热门标签
php爱好者> php文档>Command Injection

Command Injection

时间:2010-09-18  来源:Jackal Hu

The exec() function is a popular function used to execute a shell command. This is a useful and convenient way to execute shell commands, but this convenience heightens your rish. If tainted data is used to construct the string to be executed, an attacker can execute arbitrary commands.

Although you can execute shell commands in many different ways, the best practice is to be consistent ensure that you use only filtered and escaped data when constructing the string to executed. Other functions that require careful attention include passthru(), popen(), shell_exec(), and system().

escapeshellcmd()

escapeshellarg()

 

相关阅读 更多 +
排行榜 更多 +
辰域智控app

辰域智控app

系统工具 下载
网医联盟app

网医联盟app

运动健身 下载
汇丰汇选App

汇丰汇选App

金融理财 下载