[BlueOnyx:22432] escapeshellcmd disabled by default - wordpress contact form 7

Jochen Demmer jdemmer at relaix.net
Wed Oct 10 10:14:26 -05 2018


Hi,

please correct me if I'm wrong but due to recent error of a customer of
ours with wordpress / contact form 7 I have come to the following
conclusions:

* escapeshellcmd is being disabled in blue onyx by default because it's
a stupid function that should not be used and may result in security
problems
* the default mail() function in php uses escapeshellcmd itself
* wordpress uses mail() and therefore is doomed not to work flawlessly

- Why did you decide to disable escapeshellcmd by default?
- Is the only way of resolving my issue to enable escapeshellcmd?
- How can I enable escapeshellcmd only for this vsite permanently
(updateproof)?

Thank you

-- 

Jochen Demmer
System- und Netzwerkspezialist

RelAix Networks GmbH
Kackertstraße 10
52072 Aachen

Tel.:      0241 / 990001-206
Fax:       0241 / 990001-149
E-Mail:    jdemmer at relaix.net
Internet:  http://www.relaix.net/

Geschäftsführer: Thomas Neugebauer
Amtsgericht Aachen, HRB 15108






More information about the Blueonyx mailing list