Req #55181 [Opn->Ana]: Enhance security by limiting the script extension
| From: | fat@php.net | Date: | Mon, 11 Jul 2011 12:29:52 +0000 |
| Subject: | Req #55181 [Opn->Ana]: Enhance security by limiting the script extension | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-161789@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=55181&edit=1
ID: 55181
Updated by: fat@php.net
Reported by: fat@php.net
Summary: Enhance security by limiting the script extension
-Status: Open
+Status: Analyzed
Type: Feature/Change Request
Package: FPM related
Operating System: any
PHP Version: 5.3.6
-Assigned To:
+Assigned To: fat
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2011-07-11 08:29:37] fat@php.net
Description:
------------
If the web server in front of FPM is misconfigured, FPM can parse and execute PHP
code from any kind of files (test.php, test.txt, test.jpg, test.css, ...).
It should be possible to limit the extension of the primary script FPM will
execute.
Something like (in pool configuration)
security.limit_extensions = .php
if the primary script does not end with .php, an access denied is returned (403).
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=55181&edit=1