#19703 [Opn->Bgs]: safe_mode allows include-ing of http documents

From: Date: Wed, 02 Oct 2002 05:17:31 +0000
Subject: #19703 [Opn->Bgs]: safe_mode allows include-ing of http documents
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-21213@lists.php.net to get a copy of this message
ID: 19703 Updated by: yohgaki@php.net Reported By: phpbug-011002-1@smayw.nask.com -Status: Open +Status: Bogus Bug Type: *General Issues Operating System: Linux PHP Version: 4.2.3 New Comment: Not enough information was provided for us to be able to handle this bug. Please re-read the instructions at http://bugs.php.net/how-to-report.php If you can provide more information, feel free to add it to this bug and change the status back to "Open". Thank you for your interest in PHP. Previous Comments: ------------------------------------------------------------------------ [2002-10-01 21:40:44] phpbug-011002-1@smayw.nask.com I believe PHP with safe_mode enabled should not allow include-ing of files via http:// or any other remote means, if it will not allow based on permissions and open_basedir and such. The relevand portion of httpd.conf: php_admin_flag safe_mode on php_admin_value open_basedir /home/web/www.tras.pl/ php_admin_value doc_root /home/web/www.tras.pl/www/ php_admin_value safe_mode_exec_dir /usr/local/php/bin test script at: http://www.tras.pl/test-safe.php source at: http://www.tras.pl/test-safe.txt ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=19703&edit=1

« previous php.bugs (#21213) next »