Server-jacking exploits for ImageMagick are so trivial, you'll scream

I hate to defend H4rm0ny, but

If this was an SQL injection caused by home-spun quoting, everybody would condemn the coder as idiots who should have used placeholders. But because its happening on the command-line, everybody's defending it. (Ironically, the unix command-line has the potential to be a safe API: but not when the tokenisation is done by a shell.)

