Bug #17161 Updated: rmdir() bypasses safe_mode
| From: | ilia at prohost dot org | Date: | Sun, 12 May 2002 16:12:59 +0000 |
| Subject: | Bug #17161 Updated: rmdir() bypasses safe_mode | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-7486@lists.php.net to get a copy of this message | ||
ID: 17161
Updated by: ilia@prohost.org
Reported By: ilia@prohost.org
-Status: Open
+Status: Bogus
Bug Type: Scripting Engine problem
Operating System: Linux 2.4.18
PHP Version: 4.2.0
New Comment:
not a bug since only works if the directory which is being removed is
located inside a directory with the same uid as the removing script.
Previous Comments:
------------------------------------------------------------------------
[2002-05-12 10:30:07] ilia@prohost.org
rmdir() function can be used to delete directories that a user should
be able to delete under safe_mode.
Ex.
mkdir test
chmod 777 test
(gid: user pid: user)
test.php (gid: www pid: www)
<?php rmdir('test'); ?>
works!
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=17161&edit=1