Bug #11566 Updated: It appears most functions don't check open_basedir

From: Date: Sat, 07 Jul 2001 05:36:33 +0000
Subject: Bug #11566 Updated: It appears most functions don't check open_basedir
Groups: php.dev 
Request: Send a blank email to php-dev+get-59133@lists.php.net to get a copy of this message
ID: 11566 Updated by: jason Reported By: henry@metroweb.co.za Old-Status: Open Status: Closed Old-Bug Type: PHP options/info functions Bug Type: *General Issues Operating system: PHP Version: 4.0.5 Assigned To: Comments: All of the safe_mode/open_basedir functionality will eventually be redesigned -Jason Previous Comments: --------------------------------------------------------------------------- [2001-06-19 13:35:21] henry@metroweb.co.za It appears most functions that accept path/filename args don't check open_basedir. The following code needs to be added to many functions after the convert_to_string_ex function call: if (php_check_open_basedir((*filename)->value.str.val)) RETURN_FALSE; where 'filename' could of course change. (this check is typically inserted before the safe_mode check since safe_mode is often not used because of it's limiting factor for ISPs) --------------------------------------------------------------------------- ATTENTION! Do NOT reply to this email! To reply, use the web interface found at http://bugs.php.net/?id=11566&edit=2

« previous php.dev (#59133) next »