Bug #17157 Updated: fopen can bypass safe_mode

From: Date: Tue, 18 Jun 2002 23:59:02 +0000
Subject: Bug #17157 Updated: fopen can bypass safe_mode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-11304@lists.php.net to get a copy of this message
ID: 17157 Updated by: sniper@php.net Reported By: ilia@prohost.org -Status: Duplicate +Status: Closed Bug Type: Scripting Engine problem Operating System: Linux 2.4.18 PHP Version: 4.2.0 New Comment: This bug has been fixed in CVS. You can grab a snapshot of the CVS version at http://snaps.php.net/. In case this was a documentation problem, the fix will show up soon at http://www.php.net/manual/. In case this was a PHP.net website problem, the change will show up on the PHP.net site and on the mirror sites. Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2002-05-11 16:01:16] rasmus@php.net Same bug as 17156 - fixed in CVS ------------------------------------------------------------------------ [2002-05-11 15:51:17] ilia@prohost.org If a readfile() function is passed 3rd parameter, which normally indicated that the file should be opened from the "include_path", it can by pass safe_mode limitations. ex. <?php fpassthru(fopen("/etc/passwd", "r", 1)); ?> ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=17157&edit=1

« previous php.bugs (#11304) next »