#18936 [Fbk->Opn]: Causes server to crash, serious problem
| From: | theshithead at cox dot net | Date: | Sat, 17 Aug 2002 05:15:43 +0000 |
| Subject: | #18936 [Fbk->Opn]: Causes server to crash, serious problem | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-17085@lists.php.net to get a copy of this message | ||
ID: 18936
User updated by: theshithead@cox.net
Reported By: theshithead@cox.net
-Status: Feedback
+Status: Open
Bug Type: Performance problem
Operating System: Unsure
PHP Version: 4.2.0
New Comment:
That line to include a file, since I cant include login.php in my mysql
database, I include it by variable..
It might have been include('file.php'); instead, I know it was correct
though, I tested it.
Previous Comments:
------------------------------------------------------------------------
[2002-08-17 01:13:07] rasmus@php.net
No, obviously we can't. What exactly are you expecting the line:
$loginStatus = include("$path_site/login.php");
to do?
------------------------------------------------------------------------
[2002-08-17 01:10:22] theshithead@cox.net
Okay, I am going to make a full long complete example.
first off, the MySQL Database stores my themes. the theme header is
stored in the database and called upon by the var name $header.
I eval it using the code I showed earlier. All variables show just
fine. But when I call on $loginStatus I get the problem I described.
Okay I will describe the problem in short:
Header (stored in fulltext mysql database)
(ALL MY HEADER HTML)
<table><tr><td>$loginStatus</tr></td></table>
Variables.php
$path_site = "http://www.w0rms.com";
$loginStatus = include("$path_site/login.php");
themes.php (this converts the themes so the variables are defined)
Connect();
$sql = mysql_query(select from etc);
$myrow = mysql_fetch_array($sql);
$theme_id = $myrow["theme_id"];
$header = addslashes($myrow[header]);
eval("\$header = \"$header\";");
$header = stripslashes($header);
Okay, here is index.php The page were all of it comes together:
<?php
// =======================================
// Required Files
// =======================================
require("require/variables.php");
require("require/mysql.php");
require("require/functions.php");
require("require/common.php");
require("require/themes.php");
// =======================================
// We echo the header
// =======================================
echo "$header";
phphphphphphphphp---
?>
That is as deep as I can explain it, without showing the entire
scripts; can you create the same error?
------------------------------------------------------------------------
[2002-08-17 00:59:44] rasmus@php.net
include does not return anything except true/false indicating whether
the file could be included. Your $loginStatus = include and $var =
include examples make absolutely no sense. Could you please write a
really short script that causes the crash that we can try on our end?
------------------------------------------------------------------------
[2002-08-17 00:54:14] theshithead@cox.net
Okay, in my header of my site, I have user the variable $var.
I use fulltext database type, and use the following code so the
variable works:
$header = addslashes($myrow[header]);
eval("\$header = \"$header\";");
$header = stripslashes($header);
I define the $var in variables.php as
$var = include("file.php");
I echo it in my index.php, header.php
The page doesnt load, and then for several hours the server was down.
No pages worked
------------------------------------------------------------------------
[2002-08-17 00:38:01] kalowsky@php.net
so you have $var in your database, and then you overwrite it by setting
it to the return value from the included file?
Where is the bug, this works just fine for me on multiple OSes.
You may wish to try updating to 4.2.2, if only for the security fixes
in it.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/18936
--
Edit this bug report at http://bugs.php.net/?id=18936&edit=1