#21885 [Com]: move_uploaded_file error with open_basedir

From: Date: Mon, 27 Jan 2003 21:35:21 +0000
Subject: #21885 [Com]: move_uploaded_file error with open_basedir
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-31372@lists.php.net to get a copy of this message
ID: 21885 Comment by: ryan@hostbaby.com Reported By: mak77@anvi.it Status: Open Bug Type: Filesystem function related Operating System: Windows XP - IIS PHP Version: 4.3.0 New Comment: Yeah this behavior has changed, it didn't do this in 4.2.3. It seems like it *used to* bypass the open_basedir check when using move_uploaded_file on a file in upload_tmp_dir. Or rather, it added one's upload_tmp_dir to open_basedir automatically (bug 17488). Could someone comment as to whether or not this is a permanent change, and if so, perhaps document it somewhere on php.net? (FreeBSD 4.6-STABLE Apache/1.3.27 PHP/4.3.0 apxs, safe_mode=Off) Previous Comments: ------------------------------------------------------------------------ [2003-01-27 06:36:28] mak77@anvi.it no that is my writing fault on this submission :) ------------------------------------------------------------------------ [2003-01-27 05:25:48] coffee@tea.com missing _ in open_basedir ? ------------------------------------------------------------------------ [2003-01-26 05:01:33] mak77@anvi.it i've a script that worked well with 4.2.2, this scripts makes an upload my ini is set to: open basedir=. ;;;;;;;;;;;;;;;; ; File Uploads ; ;;;;;;;;;;;;;;;; ; Whether to allow HTTP file uploads. file_uploads = On ; Temporary directory for HTTP uploaded files (will use system default if not ; specified). upload_tmp_dir ="c:\temp\php-uploads" ; Maximum allowed size for uploaded files. upload_max_filesize = 6M my script does simply: move_uploaded_file($_FILES['new_file_file']['tmp_name'], $this->path.$this->filename); in my class... it gives me: Warning: move_uploaded_file() [function.move-uploaded-file.html]: open_basedir restriction in effect. File(c:\temp\php-uploads\phpD.tmp) is not within the allowed path(s): (.) in C:\neoportal\modules\mediaalbum\mediafile_class.php on line 95 it seems that a open_basedir check is made on the source file and not only on the destination file. the file is correctly uploaded to c:\temp\php-uploads\phpD.tmp but not moved to dest folder (that is a subfolder of current dir so it's in the allowed path) The same error is in PHPMYADMIN 2.3.3pl1 when i try to upload a file .sql Adding the c:\temp\ path to open basedir as ".;c:\temp\" doesn't help ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=21885&edit=1

« previous php.bugs (#31372) next »