Bug #17157 Updated: fopen can bypass safe_mode

From: Date: Sat, 11 May 2002 20:01:16 +0000
Subject: Bug #17157 Updated: fopen can bypass safe_mode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-7448@lists.php.net to get a copy of this message
ID: 17157 Updated by: rasmus@php.net Reported By: ilia@prohost.org -Status: Open +Status: Duplicate Bug Type: Scripting Engine problem Operating System: Linux 2.4.18 PHP Version: 4.2.0 New Comment: Same bug as 17156 - fixed in CVS Previous Comments: ------------------------------------------------------------------------ [2002-05-11 15:51:17] ilia@prohost.org If a readfile() function is passed 3rd parameter, which normally indicated that the file should be opened from the "include_path", it can by pass safe_mode limitations. ex. <?php fpassthru(fopen("/etc/passwd", "r", 1)); ?> ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=17157&edit=1

« previous php.bugs (#7448) next »