Bug #17157 Updated: fopen can bypass safe_mode
| From: | rasmus@php.net | Date: | Sat, 11 May 2002 20:01:16 +0000 |
| Subject: | Bug #17157 Updated: fopen can bypass safe_mode | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-7448@lists.php.net to get a copy of this message | ||
ID: 17157
Updated by: rasmus@php.net
Reported By: ilia@prohost.org
-Status: Open
+Status: Duplicate
Bug Type: Scripting Engine problem
Operating System: Linux 2.4.18
PHP Version: 4.2.0
New Comment:
Same bug as 17156 - fixed in CVS
Previous Comments:
------------------------------------------------------------------------
[2002-05-11 15:51:17] ilia@prohost.org
If a readfile() function is passed 3rd parameter, which normally
indicated that the file should be opened from the "include_path", it
can by pass safe_mode limitations.
ex.
<?php
fpassthru(fopen("/etc/passwd", "r", 1));
?>
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=17157&edit=1