Re: php4 /main fopen_wrappers.c

From: Date: Wed, 11 Jul 2001 04:45:01 +0000
Subject: Re: php4 /main fopen_wrappers.c
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-59647@lists.php.net to get a copy of this message
At 12:13 AM 7/11/2001 +0200, Jeroen van Wolffelaar wrote:
- Right now this also effects things like opening php.ini. It'll now always
    check in the current working directory for php.ini. I think this
doesn't
    screw up todays behavior.
Isn't this a huge security risk? When there is something wrong so that php.ini can't get read where it should, it will maybe read the user's one?
Can you check it and come up with a conclusive answer if it's a problem. I don't have time now.
I assume it will at least first check for php.ini where it should be?
Yes, it'll first check the real place.
By the way, when doing something like include("../init.php"), your script will get broken when a init.php is added somewhere... it doesn't make it very transparently.
In what respect? The reason why I want people to check the patch and think about it is so that we can remove it ASAP if people feel it does more harm than good. Andi

« previous php.dev (#59647) next »