PHP 4.0 Bug #9462 Updated: NULL bute eats rest of string

From: Date: Thu, 01 Mar 2001 15:34:19 +0000
Subject: PHP 4.0 Bug #9462 Updated: NULL bute eats rest of string
Groups: php.dev 
Request: Send a blank email to php-dev+get-47717@lists.php.net to get a copy of this message
ID: 9462 User Update by: tharbad@kaotik.org Status: Open Bug Type: Filesystem function related Description: NULL bute eats rest of string On my system, with something like: include($string . ".php"); I'm able to get, for example, /etc/passwd by adding a null byte to the end of $string, causing the include function to ignore the ".php" extension set on the include. Previous Comments: --------------------------------------------------------------------------- [2001-02-28 23:06:04] bbonev@php.net just error reporting functions are not binary safe. although i do not see a reason to open a file containing a null char in the name - most OSes will get the part before the first null char. lets call it bug because current behav doesn't help enough to track the problem --------------------------------------------------------------------------- [2001-02-26 09:17:33] tharbad@kaotik.org I'm not sure if this is a bug or feature, comments are apreciated. http://bugs.horde.org/show_bug.cgi?id=621 Example: <quote> include($string . ".php"); </quote> with "magic_quotes_gpc = On" (php.ini) calling test.php?string=test%00 result: Warning: Failed opening 'test

« previous php.dev (#47717) next »