Bug #17156 Updated: readfile can bypass safe_mode

From: Date: Sat, 11 May 2002 20:00:20 +0000
Subject: Bug #17156 Updated: readfile can bypass safe_mode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-7447@lists.php.net to get a copy of this message
ID: 17156 Updated by: rasmus@php.net Reported By: ilia@prohost.org -Status: Open +Status: Closed Bug Type: Scripting Engine problem Operating System: Linux 2.4.18 PHP Version: 4.2.0 New Comment: Fixed in CVS (for all functions with a safemode_include_dir switch). Note that this was only a problem if the safemode_include_dir was not defined in the php.ini file. Previous Comments: ------------------------------------------------------------------------ [2002-05-11 15:22:23] ilia@prohost.org If a readfile() function is passed 2nd parameter it can be used to read ANY file on the system regardless of safe_mode. ex. <?php readfile('/etc/passwd', 1); ?> ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=17156&edit=1

« previous php.bugs (#7447) next »