#19703 [Bgs]: safe_mode allows include-ing of http documents
| From: | yohgaki@php.net | Date: | Wed, 02 Oct 2002 05:17:56 +0000 |
| Subject: | #19703 [Bgs]: safe_mode allows include-ing of http documents | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-21214@lists.php.net to get a copy of this message | ||
ID: 19703
Updated by: yohgaki@php.net
Reported By: phpbug-011002-1@smayw.nask.com
Status: Bogus
Bug Type: *General Issues
Operating System: Linux
PHP Version: 4.2.3
New Comment:
I cannot open URLs
Previous Comments:
------------------------------------------------------------------------
[2002-10-02 00:17:31] yohgaki@php.net
Not enough information was provided for us to be able
to handle this bug. Please re-read the instructions at
http://bugs.php.net/how-to-report.php
If you can provide more information, feel free to add it
to this bug and change the status back to "Open".
Thank you for your interest in PHP.
------------------------------------------------------------------------
[2002-10-01 21:40:44] phpbug-011002-1@smayw.nask.com
I believe PHP with safe_mode enabled should not allow include-ing of
files via http:// or any other remote means, if it will not allow based
on permissions and open_basedir and such.
The relevand portion of httpd.conf:
php_admin_flag safe_mode on
php_admin_value open_basedir /home/web/www.tras.pl/
php_admin_value doc_root /home/web/www.tras.pl/www/
php_admin_value safe_mode_exec_dir /usr/local/php/bin
test script at:
http://www.tras.pl/test-safe.php
source at:
http://www.tras.pl/test-safe.txt
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=19703&edit=1