Re: Voulnerability in 3.*-4.*

From: Date: Thu, 01 Jan 1970 00:00:00 +0000
Subject: Re: Voulnerability in 3.*-4.*
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-14404@lists.php.net to get a copy of this message
> Hm... I cannot give You an access :). > So, You can simply put some debug printfs in those places to discover the > problem. Really, if everything is OK, the loop <while(....)> is not > working for the filename, and the pointer s is at the same position as > fna, so, at 0. > for example, file name /foo/foo/foo/blah > bypasses the <while> loop, when working under apache as a cgi(not a > module) without changes. I don't need access, just a little PHP example script that causes the problem. So, you are saying that: <? unlink("/foo/foo/foo/blah"); ?> Doesn't do the right thing? -Rasmus

« previous php.dev (#14404) next »