Bug #68226 [Opn->Dup]: FULLY UNABLE TO USE LOAD DATA LOCAL Startement IN Web Production Enviroments
| From: | cmb@php.net | Date: | Thu, 04 Jun 2020 08:54:48 +0000 |
| Subject: | Bug #68226 [Opn->Dup]: FULLY UNABLE TO USE LOAD DATA LOCAL Startement IN Web Production Enviroments | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-227311@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68226&edit=1
ID: 68226
Updated by: cmb@php.net
Reported by: georgy dot garnov at gmail dot com
Summary: FULLY UNABLE TO USE LOAD DATA LOCAL Startement IN
Web Production Enviroments
-Status: Open
+Status: Duplicate
Type: Bug
Package: PDO MySQL
Operating System: ALL
PHP Version: 5.6.1
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Closing this ticket as duplicate of bug #68077.
Previous Comments:
------------------------------------------------------------------------
[2015-02-03 20:14:50] phpbugs2012 at joern dot heissler dot de
See also related https://bugs.php.net/bug.php?id=62889
------------------------------------------------------------------------
[2014-10-14 15:20:08] johannes@php.net
With libmysql we can't check the path. As soon as the feature is enabled the server can request
any file it likes (Client sends SQL to server, the server parses it and requests the file, the
client doesn't know SQL) therefore on PHP versions using libmysql we can't check the path.
With mysqlnd this is different, there we can check the path. Andrey do you have any thoughts on
this? Any issues if we make this check less strict?
Security-wise "interesting" might be if a malicious server requests php://input or such.
------------------------------------------------------------------------
[2014-10-14 10:57:15] georgy dot garnov at gmail dot com
Description:
------------
If you set open_basedir in your php.ini or use php as fcgi you will always got "The used
command is not allowed with this MySQL version" error.
You can use new PDO($dsn,$login,$password, array(PDO::MYSQL_ATTR_LOCAL_INFILE => true)) but you
will have no effect.
So you are fully unable to use LOAD DATA LOCAL INFILE.
That's because of \ext\pdo_mysql\mysql_driver.c
LINES 626 to 633
#if PHP_API_VERSION < 20100412
if ((PG(open_basedir) && PG(open_basedir)[0] != '\0') || PG(safe_mode))
#else
if (PG(open_basedir) && PG(open_basedir)[0] != '\0')
#endif
{
local_infile = 0;
}
as you can see, you will always fail in production enviroments
no check if loaded file inside base dir just fail.
That's bad!!
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68226&edit=1