In my php server, I can not access exec function. How can I enable it and is it risk for my server?
1条回答 默认 最新
dtsi9484 2015-12-31 12:08关注You can enable it by disabling
safe_mode()inphp.ini.As far as whether or not you should do this for security reasons, I would say that it's a bit more secure to leave it disabled, but the risk should be minimal if you write your code in a safe manner and make sure to validate, sanitize, and properly-quote input. Using
exec()with a constant argument tends to be fairly safe. But, doing something likeexec('myprogram ' . $_POST['user_id']);is very very dangerous.To safely pass an argument to
exec();, you need to make use ofescapeshellarg():<?php if (isset($_POST['user_id'])) { $userId = $_POST['user_id']; } else { $userId = '0'; } exec('myprogram ' . escapeshellarg($userId));本回答被题主选为最佳回答 , 对您是否有帮助呢?解决 无用评论 打赏 举报