view vendor/nikic/php-parser/test/code/parser/expr/shellExec.test @ 13:5fb285c0d0e3

Update Drupal core to 8.4.7 via Composer. Security update; I *think* we've been lucky to get away with this so far, as we don't support self-registration which seems to be used by the so-called "drupalgeddon 2" attack that 8.4.5 was vulnerable to.
author Chris Cannam
date Mon, 23 Apr 2018 09:33:26 +0100
parents 4c8ae668cc8c
children
line wrap: on
line source
Shell execution
-----
<?php
``;
`test`;
`test $A`;
`test \``;
`test \"`;
-----
array(
    0: Stmt_Expression(
        expr: Expr_ShellExec(
            parts: array(
            )
        )
    )
    1: Stmt_Expression(
        expr: Expr_ShellExec(
            parts: array(
                0: Scalar_EncapsedStringPart(
                    value: test
                )
            )
        )
    )
    2: Stmt_Expression(
        expr: Expr_ShellExec(
            parts: array(
                0: Scalar_EncapsedStringPart(
                    value: test
                )
                1: Expr_Variable(
                    name: A
                )
            )
        )
    )
    3: Stmt_Expression(
        expr: Expr_ShellExec(
            parts: array(
                0: Scalar_EncapsedStringPart(
                    value: test `
                )
            )
        )
    )
    4: Stmt_Expression(
        expr: Expr_ShellExec(
            parts: array(
                0: Scalar_EncapsedStringPart(
                    value: test \"
                )
            )
        )
    )
)