Bug #17162 Updated: unlink() bypasses safe_mode & file permissions

From: Date: Sun, 12 May 2002 14:40:28 +0000
Subject: Bug #17162 Updated: unlink() bypasses safe_mode & file permissions
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-7473@lists.php.net to get a copy of this message
ID: 17162 Updated by: ilia@prohost.org Reported By: ilia@prohost.org Status: Open Bug Type: Scripting Engine problem Operating System: Linux 2.4.18 PHP Version: 4.2.0 New Comment: I forgot to add, the webserver runs as user/group "www". Previous Comments: ------------------------------------------------------------------------ [2002-05-12 10:38:59] ilia@prohost.org unlink() function can be used to delete files that user does not have permissions to delete. Ex. touch test; ls -l test; -rw-r--r-- 1 forum forum 0 May 12 10:33 test ls -l a.php -rw-rw-rw- 1 www www 35 May 12 10:33 a.php a.php: <?php unlink('test'); ?> after a.php is run via the web the file test is GONE! ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=17162&edit=1

« previous php.bugs (#7473) next »