Re: php4 /main fopen_wrappers.c
| From: | Jeroen van Wolffelaar | Date: | Tue, 10 Jul 2001 22:13:19 +0000 |
| Subject: | Re: php4 /main fopen_wrappers.c | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-59632@lists.php.net to get a copy of this message | ||
> - Right now this also effects things like opening php.ini. It'll now
always
> check in the current working directory for php.ini. I think this
doesn't
> screw up todays behavior.
Isn't this a huge security risk? When there is something wrong so that
php.ini can't get read where it should, it will maybe read the user's
one?
I assume it will at least first check for php.ini where it should be?
By the way, when doing something like include("../init.php"), your
script will get broken when a init.php is added somewhere...
it doesn't make it very transparently.
Jeroen