Bug #11566: It appears most functions don't check open_basedir
| From: | henry at metroweb dot co dot za | Date: | Tue, 19 Jun 2001 17:35:22 +0000 |
| Subject: | Bug #11566: It appears most functions don't check open_basedir | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-57288@lists.php.net to get a copy of this message | ||
From: henry@metroweb.co.za
Operating system: linux
PHP version: 4.0.5
PHP Bug Type: PHP options/info functions
Bug description: It appears most functions don't check open_basedir
It appears most functions that accept path/filename args don't check open_basedir. The
following code needs to be added to many functions after the convert_to_string_ex function call:
if (php_check_open_basedir((*filename)->value.str.val)) RETURN_FALSE;
where 'filename' could of course change.
(this check is typically inserted before the safe_mode check since safe_mode is often not used
because of it's limiting factor for ISPs)
--
Edit Bug report at: http://bugs.php.net/?id=11566&edit=1