Bug #46925 [Opn]: when open_basedir="." the working directory is set to the executable location
| From: | cmb@php.net | Date: | Mon, 03 May 2021 12:18:19 +0000 |
| Subject: | Bug #46925 [Opn]: when open_basedir="." the working directory is set to the executable location | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-233657@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=46925&edit=1
ID: 46925
Updated by: cmb@php.net
Reported by: eyal at zend dot com
Summary: when open_basedir="." the working directory is set
to the executable location
Status: Open
Type: Bug
Package: Safe Mode/open_basedir
Operating System: Windows *
PHP Version: 5.2.8
Block user comment: N
Private report: N
New Comment:
We even document[1]:
| The special value . indicates that the working directory of the
| script will be used as the base-directory.
[1] <https://www.php.net/manual/en/ini.core.php#ini.open-basedir>
Previous Comments:
------------------------------------------------------------------------
[2021-05-03 12:15:42] cmb@php.net
Related To: Bug #77474
------------------------------------------------------------------------
[2008-12-23 15:00:29] pajoye@php.net
Do we really want to support relative path? It may (incidentally) have worked before but I
can't think of any sane usage of a relative path for open_basedir.
------------------------------------------------------------------------
[2008-12-22 11:55:29] eyal at zend dot com
Description:
------------
NOTE: Tested with FastCGI module on IIS 7.
1. Verify you have info.php in your docroot.
2. Set the directive open_basedir="."
3. Request the script info.php
Reproduce code:
---------------
<?php phpinfo(): ?>
Expected result:
----------------
The phpinfo() output
Actual result:
--------------
PHP Warning: Unknown: open_basedir restriction in effect. File(C:\inetpub\wwwroot\info.php) is not
within the allowed path(s): (.) in Unknown on line 0
To verify the location that is not restricted you can do the following:
Add a virtual directory to the default web site with a physical path of the php-fastCGI.exe and put
the info.php there as well.
Now you can see that when requesting the file from the virtual directory you will receive the
phpinfo() output.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=46925&edit=1