Bug #72253 [Com]: phpinfo shows only first block of admin_value[disable_functions]

From: Date: Mon, 23 May 2016 19:31:18 +0000
Subject: Bug #72253 [Com]: phpinfo shows only first block of admin_value[disable_functions]
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201247@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72253&edit=1

 ID:                 72253
 Comment by:         witekfl at gazeta dot pl
 Reported by:        witekfl at gazeta dot pl
 Summary:            phpinfo shows only first block of
                     admin_value[disable_functions]
 Status:             Feedback
 Type:               Bug
 Package:            FPM related
 Operating System:   Linux
 PHP Version:        7.0.6
 Block user comment: N
 Private report:     N

 New Comment:

<?php
error_reporting(E_ALL);
echo 'disable_functions=', ini_get('disable_functions'), "\n";
echo 'sin(0)=', sin(0), "\n";
echo 'cos(0)=', cos(0), "\n";
echo 'tan(0)=', tan(0), "\n";


 disable_functions=sin sin(0)=                                                                      
                                       
   Warning: sin() has been disabled for security reasons in /home/www/v2.6.5/info.php on line 4     
                                         
   cos(0)=                                                                                          
                                         
   Warning: cos() has been disabled for security reasons in /home/www/v2.6.5/info.php on line 5     
                                         
   tan(0)=                                                                                          
                                         
   Warning: tan() has been disabled for security reasons in /home/www/v2.6.5/info.php on line 6


Previous Comments:
------------------------------------------------------------------------
[2016-05-23 19:09:14] requinix@php.net

If you do
  php_admin_value[disable_functions]=sin
  php_admin_value[disable_functions]=cos
  php_admin_value[disable_functions]=tan
what does phpinfo() say, what does ini_get("disable_functions") return, and which of those
functions do/do not work?

------------------------------------------------------------------------
[2016-05-23 17:43:44] fa@php.net

Disregard my last comment.

------------------------------------------------------------------------
[2016-05-23 17:41:46] fa@php.net

reproducible on 7.0.5 CLI as well:

php -n -d "disable_functions=phpinfo" -d "disable_functions=exec" -r
"phpinfo();echo exec('ls');" | grep disable_

disable_functions => exec => exec

------------------------------------------------------------------------
[2016-05-23 14:52:02] witekfl at gazeta dot pl

php_admin_value[disable_functions] = leak                                                           
                                         
php_admin_value[disable_functions] = phpinfo                                                        
                                         
php_admin_value[disable_functions] = exec
<?php
error_reporting(E_ALL);
phpinfo();

Warning: phpinfo() has been disabled for security reasons in /home/www/info.php on line 3

Could you check it first, please?

------------------------------------------------------------------------
[2016-05-22 21:04:07] requinix@php.net

php_admin_value defines a setting that cannot be overridden. The second line is ignored because it
is attempting to override the disable_function set earlier.

disable_functions is a comma-separated list of functions. Your configuration should read
  php_admin_value[disable_functions] = curl_init,curl_close

http://php.net/manual/en/ini.core.php#ini.disable-functions

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=72253


--
Edit this bug report at https://bugs.php.net/bug.php?id=72253&edit=1


Thread (10 messages)

« previous php.bugs (#201247) next »