Bug #17162 Updated: unlink() bypasses safe_mode

From: Date: Sun, 12 May 2002 14:41:27 +0000
Subject: Bug #17162 Updated: unlink() bypasses safe_mode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-7474@lists.php.net to get a copy of this message
ID: 17162 Updated by: derick@php.net -Summary: unlink() bypasses safe_mode & file permissions Reported By: ilia@prohost.org Status: Open Bug Type: Scripting Engine problem Operating System: Linux 2.4.18 PHP Version: 4.2.0 New Comment: This has nothing to do with file permissions, update summary Derick Previous Comments: ------------------------------------------------------------------------ [2002-05-12 10:40:27] ilia@prohost.org I forgot to add, the webserver runs as user/group "www". ------------------------------------------------------------------------ [2002-05-12 10:38:59] ilia@prohost.org unlink() function can be used to delete files that user does not have permissions to delete. Ex. touch test; ls -l test; -rw-r--r-- 1 forum forum 0 May 12 10:33 test ls -l a.php -rw-rw-rw- 1 www www 35 May 12 10:33 a.php a.php: <?php unlink('test'); ?> after a.php is run via the web the file test is GONE! ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=17162&edit=1

« previous php.bugs (#7474) next »