MySQL - LOAD DATA LOCAL INFILE
| From: | Georg Richter | Date: | Fri, 09 Aug 2002 00:12:06 +0000 |
| Subject: | MySQL - LOAD DATA LOCAL INFILE | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-86676@lists.php.net to get a copy of this message | ||
Hi, s
since MySQL-Version 3.23.49 and 4.0.2 the LOAD DATA LOCAL INFILE
option is disabled by default, unless the server and client supports it.
With an external libmysql (and also with the integrated libmysql, which
doesn't support disable load data), we have a "little" security hole,
because in safe_mode it is possible to load (and view) all the data, which
is under access of the webserver).
I would like to disable LOAD DATA LOCAL INFILE in safe mode. However this
will generate a lot of trouble, since users without shell access aren't able
to import data in their mysql-db.
Any opinions/suggestions?
Georg