3 ms·
Even escapeshellarg might not be enough, because the command you are executing might trying to parse it as options. Depends on which command you are using, it c
by maple3142 5y ago
Even escapeshellarg might not be enough, because the command you are executing might trying to parse it as options. Depends on which command you are using, it could be exploitable. For example, there is a CTF challenge where you need to get RCE by passing a argument to wget escaped by escapeshellarg. (https://github.com/CykuTW/My-CTF-Challenges/blob/master/TSJ-CTF-2022/wgetshell/solution/README.md https://github.com/CykuTW/My-CTF-Challenges/blob/master/TSJ-...)