Bug #11566 Updated: It appears most functions don't check open_basedir
| From: | jason@php.net | Date: | Sat, 07 Jul 2001 05:36:33 +0000 |
| Subject: | Bug #11566 Updated: It appears most functions don't check open_basedir | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-59133@lists.php.net to get a copy of this message | ||
ID: 11566
Updated by: jason
Reported By: henry@metroweb.co.za
Old-Status: Open
Status: Closed
Old-Bug Type: PHP options/info functions
Bug Type: *General Issues
Operating system:
PHP Version: 4.0.5
Assigned To:
Comments:
All of the safe_mode/open_basedir functionality will eventually be redesigned
-Jason
Previous Comments:
---------------------------------------------------------------------------
[2001-06-19 13:35:21] henry@metroweb.co.za
It appears most functions that accept path/filename args don't check open_basedir. The
following code needs to be added to many functions after the convert_to_string_ex function call:
if (php_check_open_basedir((*filename)->value.str.val)) RETURN_FALSE;
where 'filename' could of course change.
(this check is typically inserted before the safe_mode check since safe_mode is often not used
because of it's limiting factor for ISPs)
---------------------------------------------------------------------------
ATTENTION! Do NOT reply to this email!
To reply, use the web interface found at http://bugs.php.net/?id=11566&edit=2