Re: PHP 4.0 Bug #5097 Updated: security hole in file open
| From: | Greg | Date: | Sat, 17 Jun 2000 05:46:01 +0000 |
| Subject: | Re: PHP 4.0 Bug #5097 Updated: security hole in file open | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-21587@lists.php.net to get a copy of this message | ||
I am currently running in safe mode on our php3 enabled server and this
is still accessable
please see http://www.netserv.net.au/witchy/info.php3
It appears then that this is a feature request
As I still would like to allow the users to be able just add .php
files in there web directory to save conffusion
Is there no way to basically chroot all scripts to the directory they
are run from then disallow access below this point
Thanks Greg
Bug Database wrote:
>
> ID: 5097
> Updated by: rasmus
> Reported By: greg@netserv.net.au
> Status: Closed
> Bug Type: Other
> Assigned To:
> Comments:
>
> Turn on safe-mode or run PHP as a CGI under suexec
>
> Full Bug description available at:
> http://bugs.php.net/version4/?id=5097