Bug #17162 Updated: unlink() bypasses safe_mode & file permissions
| From: | ilia at prohost dot org | Date: | Sun, 12 May 2002 14:40:28 +0000 |
| Subject: | Bug #17162 Updated: unlink() bypasses safe_mode & file permissions | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-7473@lists.php.net to get a copy of this message | ||
ID: 17162
Updated by: ilia@prohost.org
Reported By: ilia@prohost.org
Status: Open
Bug Type: Scripting Engine problem
Operating System: Linux 2.4.18
PHP Version: 4.2.0
New Comment:
I forgot to add, the webserver runs as user/group "www".
Previous Comments:
------------------------------------------------------------------------
[2002-05-12 10:38:59] ilia@prohost.org
unlink() function can be used to delete files that user does not have
permissions to delete.
Ex.
touch test;
ls -l test;
-rw-r--r-- 1 forum forum 0 May 12 10:33 test
ls -l a.php
-rw-rw-rw- 1 www www 35 May 12 10:33 a.php
a.php:
<?php unlink('test'); ?>
after a.php is run via the web the file test is GONE!
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=17162&edit=1