Bug #17162 Updated: unlink() bypasses safe_mode
| From: | rasmus@php.net | Date: | Sun, 12 May 2002 15:46:08 +0000 |
| Subject: | Bug #17162 Updated: unlink() bypasses safe_mode | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-7482@lists.php.net to get a copy of this message | ||
ID: 17162
Updated by: rasmus@php.net
Reported By: ilia@prohost.org
-Status: Open
+Status: Bogus
Bug Type: Scripting Engine problem
Operating System: Linux 2.4.18
PHP Version: 4.2.0
New Comment:
Also not a bug, you can unlink files in directories you own. In this
case "directories you own" means a directory owned by the user id that
owns the current script.
Previous Comments:
------------------------------------------------------------------------
[2002-05-12 10:41:26] derick@php.net
This has nothing to do with file permissions, update summary
Derick
------------------------------------------------------------------------
[2002-05-12 10:40:27] ilia@prohost.org
I forgot to add, the webserver runs as user/group "www".
------------------------------------------------------------------------
[2002-05-12 10:38:59] ilia@prohost.org
unlink() function can be used to delete files that user does not have
permissions to delete.
Ex.
touch test;
ls -l test;
-rw-r--r-- 1 forum forum 0 May 12 10:33 test
ls -l a.php
-rw-rw-rw- 1 www www 35 May 12 10:33 a.php
a.php:
<?php unlink('test'); ?>
after a.php is run via the web the file test is GONE!
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=17162&edit=1