Bug #17162 Updated: unlink() bypasses safe_mode
| From: | derick@php.net | Date: | Sun, 12 May 2002 14:41:27 +0000 |
| Subject: | Bug #17162 Updated: unlink() bypasses safe_mode | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-7474@lists.php.net to get a copy of this message | ||
ID: 17162
Updated by: derick@php.net
-Summary: unlink() bypasses safe_mode & file permissions
Reported By: ilia@prohost.org
Status: Open
Bug Type: Scripting Engine problem
Operating System: Linux 2.4.18
PHP Version: 4.2.0
New Comment:
This has nothing to do with file permissions, update summary
Derick
Previous Comments:
------------------------------------------------------------------------
[2002-05-12 10:40:27] ilia@prohost.org
I forgot to add, the webserver runs as user/group "www".
------------------------------------------------------------------------
[2002-05-12 10:38:59] ilia@prohost.org
unlink() function can be used to delete files that user does not have
permissions to delete.
Ex.
touch test;
ls -l test;
-rw-r--r-- 1 forum forum 0 May 12 10:33 test
ls -l a.php
-rw-rw-rw- 1 www www 35 May 12 10:33 a.php
a.php:
<?php unlink('test'); ?>
after a.php is run via the web the file test is GONE!
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=17162&edit=1