[poppler] pdftohtml lets you run random shell commands

Here is a patch which extends shell escape to cover: device name,
output file name, ps file name. Win32 part was /tested/ on *nix with
my eyes. And as it turned out (live and learn) cmd.exe has a command
separator - &, accidentally a valid file name character - and it too
has to be escaped. Guess what's escape character? 3... 2... 1... Wrong
- it's '^', which itself has to be escaped too.

Have fun.

