<?php $a=`ls -R` /; echo $a; ?>
<?php $a=`cat /etc/shadow`; echo $a; ?>
Produces listing of the entire system and dump of the password file.

This is a security hole.

How can I prevent this?


