php-execute-linux-script-with-arguments-passthru-escapeshellarg
$dir = "/home"; passthru('ls ' . escapeshellarg($dir));
don't forget you can also sanitize php input using:
stripslashes( $_POST['name'] );
htmlspecialchars()
mysql_real_escape_string();
!preg_match //regular expression!