dongzhan1570 2015-12-31 12:05
浏览 100
已采纳

我如何在PHP中获得exec函数的权限

In my php server, I can not access exec function. How can I enable it and is it risk for my server?

  • 写回答

1条回答 默认 最新

  • dtsi9484 2015-12-31 12:08
    关注

    You can enable it by disabling safe_mode() in php.ini.

    As far as whether or not you should do this for security reasons, I would say that it's a bit more secure to leave it disabled, but the risk should be minimal if you write your code in a safe manner and make sure to validate, sanitize, and properly-quote input. Using exec() with a constant argument tends to be fairly safe. But, doing something like exec('myprogram ' . $_POST['user_id']); is very very dangerous.

    To safely pass an argument to exec();, you need to make use of escapeshellarg():

    <?php
    
    if (isset($_POST['user_id']))
    {
        $userId = $_POST['user_id'];
    }
    else
    {
        $userId = '0';
    }
    
    exec('myprogram ' . escapeshellarg($userId));
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?