文章详情

  • 游戏榜单
  • 软件榜单
关闭导航
热搜榜
热门下载
热门标签
php爱好者> php文档>Command Injection

Command Injection

时间:2010-09-18  来源:Jackal Hu

The exec() function is a popular function used to execute a shell command. This is a useful and convenient way to execute shell commands, but this convenience heightens your rish. If tainted data is used to construct the string to be executed, an attacker can execute arbitrary commands.

Although you can execute shell commands in many different ways, the best practice is to be consistent ensure that you use only filtered and escaped data when constructing the string to executed. Other functions that require careful attention include passthru(), popen(), shell_exec(), and system().

escapeshellcmd()

escapeshellarg()

 

相关阅读 更多 +
排行榜 更多 +
掌上皇御

掌上皇御

金融理财 下载
天翼校园

天翼校园

系统软件 下载
源新闻

源新闻

浏览阅读 下载