<HTML ><HEAD ><TITLE >escapeshellarg</TITLE ><META NAME="GENERATOR" CONTENT="Modular DocBook HTML Stylesheet Version 1.7"><LINK REL="HOME" TITLE="PHP Manual" HREF="index.html"><LINK REL="UP" TITLE="Program Execution functions" HREF="ref.exec.html"><LINK REL="PREVIOUS" TITLE="Program Execution functions" HREF="ref.exec.html"><LINK REL="NEXT" TITLE="escapeshellcmd" HREF="function.escapeshellcmd.html"><META HTTP-EQUIV="Content-type" CONTENT="text/html; charset=ISO-8859-1"></HEAD ><BODY CLASS="refentry" BGCOLOR="#FFFFFF" TEXT="#000000" LINK="#0000FF" VLINK="#840084" ALINK="#0000FF" ><DIV CLASS="NAVHEADER" ><TABLE SUMMARY="Header navigation table" WIDTH="100%" BORDER="0" CELLPADDING="0" CELLSPACING="0" ><TR ><TH COLSPAN="3" ALIGN="center" >PHP Manual</TH ></TR ><TR ><TD WIDTH="10%" ALIGN="left" VALIGN="bottom" ><A HREF="ref.exec.html" ACCESSKEY="P" >Prev</A ></TD ><TD WIDTH="80%" ALIGN="center" VALIGN="bottom" ></TD ><TD WIDTH="10%" ALIGN="right" VALIGN="bottom" ><A HREF="function.escapeshellcmd.html" ACCESSKEY="N" >Next</A ></TD ></TR ></TABLE ><HR ALIGN="LEFT" WIDTH="100%"></DIV ><H1 ><A NAME="function.escapeshellarg" ></A >escapeshellarg</H1 ><DIV CLASS="refnamediv" ><A NAME="AEN78710" ></A ><P > (PHP 4 >= 4.0.3)</P >escapeshellarg -- escape a string to be used as a shell argument</DIV ><DIV CLASS="refsect1" ><A NAME="AEN78713" ></A ><H2 >Description</H2 >string <B CLASS="methodname" >escapeshellarg</B > ( string arg)<BR ></BR ><P > <B CLASS="function" >escapeshellarg()</B > adds single quotes around a string and quotes/escapes any existing single quotes allowing you to pass a string directly to a shell function and having it be treated as a single safe argument. This function should be used to escape individual arguments to shell functions coming from user input. The shell functions include <A HREF="function.exec.html" ><B CLASS="function" >exec()</B ></A >, <A HREF="function.system.html" ><B CLASS="function" >system()</B ></A > and the <A HREF="language.operators.execution.html" >backtick operator</A >. A standard use would be:</P ><P > <DIV CLASS="informalexample" ><A NAME="AEN78727" ></A ><P ></P ><TABLE BORDER="0" BGCOLOR="#E0E0E0" CELLPADDING="5" ><TR ><TD ><PRE CLASS="php" >system("ls ".escapeshellarg($dir));</PRE ></TD ></TR ></TABLE ><P ></P ></DIV > </P ><P > See also <A HREF="function.exec.html" ><B CLASS="function" >exec()</B ></A >, <A HREF="function.popen.html" ><B CLASS="function" >popen()</B ></A >, <A HREF="function.system.html" ><B CLASS="function" >system()</B ></A >, and the <A HREF="language.operators.execution.html" >backtick operator</A >. </P ></DIV ><DIV CLASS="NAVFOOTER" ><HR ALIGN="LEFT" WIDTH="100%"><TABLE SUMMARY="Footer navigation table" WIDTH="100%" BORDER="0" CELLPADDING="0" CELLSPACING="0" ><TR ><TD WIDTH="33%" ALIGN="left" VALIGN="top" ><A HREF="ref.exec.html" ACCESSKEY="P" >Prev</A ></TD ><TD WIDTH="34%" ALIGN="center" VALIGN="top" ><A HREF="index.html" ACCESSKEY="H" >Home</A ></TD ><TD WIDTH="33%" ALIGN="right" VALIGN="top" ><A HREF="function.escapeshellcmd.html" ACCESSKEY="N" >Next</A ></TD ></TR ><TR ><TD WIDTH="33%" ALIGN="left" VALIGN="top" >Program Execution functions</TD ><TD WIDTH="34%" ALIGN="center" VALIGN="top" ><A HREF="ref.exec.html" ACCESSKEY="U" >Up</A ></TD ><TD WIDTH="33%" ALIGN="right" VALIGN="top" >escapeshellcmd</TD ></TR ></TABLE ></DIV ></BODY ></HTML >