Bug #4367: read source code of ANY file on the server
| From: | alex at twoteeth dot net | Date: | Wed, 10 May 2000 01:24:47 +0000 |
| Subject: | Bug #4367: read source code of ANY file on the server | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-18559@lists.php.net to get a copy of this message | ||
From: alex@twoteeth.net
Operating system: FreeBSD 3.4-RELEASE
PHP version: 3.0.16
PHP Bug Type: Other
Bug description: read source code of ANY file on the server
ok mysql.php3 is in /home/httpd/htdocs/
and show_source.php3 is in /home/mystik/public_html/
here's a sample script that the user "mystik" created:
<?
print("<pre>");
system("cat /home/httpd/htdocs/mysql.php3");
print("</pre>");
?>
Obviously you can see what that does. Is there a way to configure apache or the php3.ini file to
make it impossible for the user to access that specific file ?
I read the security section in the manual and i saw something about user_dir and doc_root. It's
not too clear on how to set the, etc.
Please look into this.
Regards