Bug #17163 Updated: rename() bypasses safe_mode
| From: | rasmus@php.net | Date: | Sun, 12 May 2002 15:18:03 +0000 |
| Subject: | Bug #17163 Updated: rename() bypasses safe_mode | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-7477@lists.php.net to get a copy of this message | ||
ID: 17163
Updated by: rasmus@php.net
Reported By: ilia@prohost.org
-Status: Open
+Status: Bogus
Bug Type: Scripting Engine problem
Operating System: Linux 2.4.18
PHP Version: 4.2.0
New Comment:
Actually, we allow a rename in a directory if that directory is owned
by the same user id as the running script. So this one is not a bug.
Verify this statement and re-open if you find that this is not the
case.
Previous Comments:
------------------------------------------------------------------------
[2002-05-12 11:00:06] ilia@prohost.org
rename() function can be used to rename files a user has no access to
according to safe_mode.
Ex.
touch test
<?php rename('test', 'test2'); ?>
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=17163&edit=1