Bug #13060: "allow_url_fopen = On" disables safe_mode UID check
| From: | admin at kontent dot de | Date: | Thu, 30 Aug 2001 15:03:15 +0000 |
| Subject: | Bug #13060: "allow_url_fopen = On" disables safe_mode UID check | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-64724@lists.php.net to get a copy of this message | ||
From: admin@kontent.de
Operating system: Linux
PHP version: 4.0.6
PHP Bug Type: *Configuration Issues
Bug description: "allow_url_fopen = On" disables safe_mode UID check
When I turn off allow_url_fopen in php.ini the safe_mode UID check seems to
be disabled.
With "allow_url_fopen = on" an include("/etc/passwd") returns the following
error:
"The script whose uid is 10000 is not allowed to access /etc/passwd owned
by uid 0"
after I've changed the settings to "allow_url_fopen = off" the inclusion
works fine, so there is no way to prevent customers from including external
files and local system files.
--
Edit bug report at: http://bugs.php.net/?id=13060&edit=1