#19703 [Opn->Bgs]: safe_mode allows include-ing of http documents
| From: | yohgaki@php.net | Date: | Wed, 02 Oct 2002 05:17:31 +0000 |
| Subject: | #19703 [Opn->Bgs]: safe_mode allows include-ing of http documents | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-21213@lists.php.net to get a copy of this message | ||
ID: 19703
Updated by: yohgaki@php.net
Reported By: phpbug-011002-1@smayw.nask.com
-Status: Open
+Status: Bogus
Bug Type: *General Issues
Operating System: Linux
PHP Version: 4.2.3
New Comment:
Not enough information was provided for us to be able
to handle this bug. Please re-read the instructions at
http://bugs.php.net/how-to-report.php
If you can provide more information, feel free to add it
to this bug and change the status back to "Open".
Thank you for your interest in PHP.
Previous Comments:
------------------------------------------------------------------------
[2002-10-01 21:40:44] phpbug-011002-1@smayw.nask.com
I believe PHP with safe_mode enabled should not allow include-ing of
files via http:// or any other remote means, if it will not allow based
on permissions and open_basedir and such.
The relevand portion of httpd.conf:
php_admin_flag safe_mode on
php_admin_value open_basedir /home/web/www.tras.pl/
php_admin_value doc_root /home/web/www.tras.pl/www/
php_admin_value safe_mode_exec_dir /usr/local/php/bin
test script at:
http://www.tras.pl/test-safe.php
source at:
http://www.tras.pl/test-safe.txt
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=19703&edit=1