2009-07-07 18 views

回答

7

看看exec()escapeshellarg()

exec('command -param=' . escapeshellarg($_GET['argument'])); 
+0

確保您列入白名單,這些參數!有人可以嘗試發送&argument = foo%20%38%38%20rm%20-rf%20%47。那就是:命令-param = foo && rm -rf/ – 2009-07-07 09:38:15