Bug #17169 Updated: include_path allows bypass of safe_mode

From: Date: Tue, 16 Jul 2002 13:34:58 +0000
Subject: Bug #17169 Updated: include_path allows bypass of safe_mode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-14311@lists.php.net to get a copy of this message
ID: 17169 Updated by: jflemer@php.net Reported By: ilia@prohost.org -Status: Feedback +Status: Closed Bug Type: Performance problem Operating System: Linux 2.4.18 PHP Version: 4.2.0 New Comment: Thank you for your bug report. This issue has already been fixed in the latest released version of PHP, which you can download at http://www.php.net/downloads.php Works in 4.2.1. Put an echo "Safe mode: " . ini_get('safe_mode'); in there, and make sure the script isn't owned by the same user as /etc/passwd. Previous Comments: ------------------------------------------------------------------------ [2002-05-20 12:42:03] mfischer@php.net Is this still an issue or just a configuraion/whatever problem? ------------------------------------------------------------------------ [2002-05-13 03:35:51] sitnikov@infonet.ee I has test this on 4.1.2 & 4.2.0 and it not work for me. ------------------------------------------------------------------------ [2002-05-12 19:16:58] ilia@prohost.org By setting include_path setting to any directory readable to the webserver it is possible to read files from the directory regardless of safe_mode limitations. Ex. <?php ini_set('include_path', '/etc/'); include('passwd'); ?> ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=17169&edit=1

« previous php.bugs (#14311) next »