Re: php4 /main fopen_wrappers.c
| From: | Andi Gutmans | Date: | Wed, 11 Jul 2001 04:45:01 +0000 |
| Subject: | Re: php4 /main fopen_wrappers.c | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-59647@lists.php.net to get a copy of this message | ||
At 12:13 AM 7/11/2001 +0200, Jeroen van Wolffelaar wrote:
- Right now this also effects things like opening php.ini. It'll now alwaysCan you check it and come up with a conclusive answer if it's a problem. I don't have time now.check in the current working directory for php.ini. I think thisdoesn'tscrew up todays behavior.Isn't this a huge security risk? When there is something wrong so that php.ini can't get read where it should, it will maybe read the user's one?
I assume it will at least first check for php.ini where it should be?Yes, it'll first check the real place.
By the way, when doing something like include("../init.php"), your script will get broken when a init.php is added somewhere... it doesn't make it very transparently.In what respect? The reason why I want people to check the patch and think about it is so that we can remove it ASAP if people feel it does more harm than good. Andi