PHP 4.0 Bug #7606: Security Hole
| From: | exothermic at softhome dot net | Date: | Fri, 03 Nov 2000 00:22:51 +0000 |
| Subject: | PHP 4.0 Bug #7606: Security Hole | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-36879@lists.php.net to get a copy of this message | ||
From: exothermic@softhome.net
Operating system: Linux
PHP version: 4.0.3pl1
PHP Bug Type: Feature/Change Request
Bug description: Security Hole
With a multi user system we cannot secure any database driven webapplications that use php. Every
file that apache "sees" must be at least readable by every other user. Since php runs as
the same user as Apache then that includes the files that contain database logins and passwords. I
know there is a way around this using CGI but I would rather not. When will there be a solution to
this?
--
Edit Bug report at: http://bugs.php.net/?id=7606&edit=1