3 ms·
While this should be fixed, I think it's always a bad idea to rely on implementation details for safety. By which I mean those filters exist for something other
by wanderr 5y ago
While this should be fixed, I think it's always a bad idea to rely on implementation details for safety. By which I mean those filters exist for something other than protecting a system command from injection. Even if they did work properly today, there's nothing saying that this couldn't change in the future because what's considered a valid domain changes. In this case it seems like escapeshellcmd would be more appropriate.