opendir security hole
| From: | daniel | Date: | Thu, 23 May 2002 13:22:59 +0000 |
| Subject: | opendir security hole | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-84296@lists.php.net to get a copy of this message | ||
hi i am creating a webbased filemanager for uploading files to the database,
to determin which dir i upload to i have the directory in the query string
ie ?dir=blah , i have found a security flaw where if you type
dir=../../../../ it will show you the root dir of the server , how can i
lock into a directory when using opendir ? please let me know thanks