Bug #9526 Updated: Copy function is not affected by the security settings
| From: | derick@php.net | Date: | Mon, 07 May 2001 16:57:15 +0000 |
| Subject: | Bug #9526 Updated: Copy function is not affected by the security settings | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-54266@lists.php.net to get a copy of this message | ||
ID: 9526
Updated by: derick
Reported By: victor.dias-fernandes@cec.eu.int
Old-Status: Open
Status: Critical
Bug Type: Unknown/Other Function
Operating system:
PHP Version: 4.0.4pl1
Assigned To:
Comments:
Marking as fix before 4.0.6
Previous Comments:
---------------------------------------------------------------------------
[2001-03-02 09:45:59] victor.dias-fernandes@cec.eu.int
It appears that the copy function is not affected by the security restrictions set on the php.ini
file
PHP.ini:
Safe_mode=On
Open_basedir=d:wwwhtdocs
With a script like:
print('<font color=#007700>Try to copy() c:winntwin.ini to
d:wwwhtdocsphptest</tr></font><br>');
if (!copy('c:winntwin.ini', 'd:wwwhtdocsphptestwin.ini')) {
print('<font color=#007700><b>OK</b>: Copy() Failed</font>');
}
else
{
print('<font color=#DD0000><b>Warning</b>: Copy()
Succeeded!!!</font>');
}
print('<br>=====================================================<br>');
print('<font color=#007700>Try to fopen() file
d:wwwhtdocsphptestwin.ini</font><br>');
if (!fopen( 'd:wwwhtdocsphptestwin.ini', 'r' )) {
print('<font color=#007700><b>OK</b>: Fopen() Failed</font>');
}
else
{
print('<font color=#DD0000><b>Warning</b>: Fopen()
Succeeded!!!</font>');
}
I can copy a file from a forbiden directory to an allowed one and the read it.
Other functions that I have tested don't have this "bug".
I tested with Apache for Windows 1.3.14 and the PHP4 module
Best regards,
Victor Fernandes
---------------------------------------------------------------------------
ATTENTION! Do NOT reply to this email!
To reply, use the web interface found at http://bugs.php.net/?id=9526&edit=2