How php works -l?


My colleague claims that if we write back Dor in ./index.php and check this file by command
exec('php -l ./index.php');
then, they say the code executes and back Dor realno work.

I'm in the same turn, argue that this code will not work and will only occur syntax checking.

Please judge who is right!
Thank you!
July 8th 19 at 16:02
2 answers
July 8th 19 at 16:04
And what hinders to check it yourself? Judging by the dock, you're right.
July 8th 19 at 16:06
If there are vulnerabilities in the PHP parser, then nothing will.

