Security issues with using PHPs escapeshellarg

Published
2025-09-17T14:05:53.526+02:00 13 November 2013
Using user supplied data on the command line is traditionally a security disaster waiting to happen.

Using user supplied data on the command line is traditionally a security disaster waiting to happen. In an infinite universe there are however times when you might need to do just that. You will be glad to know that PHP provides two functions to aid you with security in those situations:escapeshellcmd and escapeshellarg.

Read the full post and explore our Technical Blog here.

Related stories
Showing 340 results
Get in touch
Eldar Marcussen

Cyber Security Consultant