#21885 [Com]: move_uploaded_file error with open_basedir
| From: | mak77 at supereva dot it | Date: | Tue, 28 Jan 2003 09:03:54 +0000 |
| Subject: | #21885 [Com]: move_uploaded_file error with open_basedir | ||
| References: | 1 | Groups: | php.doc |
| Request: | Send a blank email to phpdoc+get-969351369@lists.php.net to get a copy of this message | ||
ID: 21885
Comment by: mak77@supereva.it
Reported By: mak77@anvi.it
Status: Open
Bug Type: Documentation problem
Operating System: Windows XP - IIS
PHP Version: 4.3.0
New Comment:
thank you...
but adding a path to open basedir doesn't do the job
it continue to say
File(c:\temp\php-uploads\phpD.tmp) is not within the allowed path(s):
(.)
Previous Comments:
------------------------------------------------------------------------
[2003-01-28 02:21:49] philip@php.net
Is upload_tmp_dir affected by these? In otherwords, does the
upload_tmp_dir need to be listed in open_basedir?
Where does safe_mode come into play?
Please provide some documentable information as neither of these bug
reports do. #16128 says it's fixed but what does that mean?
------------------------------------------------------------------------
[2003-01-27 23:27:16] sniper@php.net
This was changed because of this bug:
http://bugs.php.net/bug.php?id=16128&edit=1
And it will stay. Reclassified as documentation prob.
------------------------------------------------------------------------
[2003-01-27 17:11:21] info@ofek.com
yes - i have the same problem with php running as cgi in windows 2000
pro with IIS. it used to work just fine, but now with 4.3.0 i get the
same error. it seems like this is a bug, because the documentation
specifically says:
move_uploaded_file() is not affected by the normal safe-mode
UID-restrictions. This is not unsafe because move_uploaded_file() only
operates on files uploaded via PHP.
even though open_basedir is not safe_mode i think the same logic should
apply!
meanwhile i'll just add the temp dir to open_basedir is a quickfix.
------------------------------------------------------------------------
[2003-01-27 15:35:20] ryan@hostbaby.com
Yeah this behavior has changed, it didn't do this in 4.2.3. It seems
like it *used to* bypass the open_basedir check when using
move_uploaded_file on a file in upload_tmp_dir. Or rather, it added
one's upload_tmp_dir to open_basedir automatically (bug 17488).
Could someone comment as to whether or not this is a permanent change,
and if so, perhaps document it somewhere on php.net?
(FreeBSD 4.6-STABLE Apache/1.3.27 PHP/4.3.0 apxs, safe_mode=Off)
------------------------------------------------------------------------
[2003-01-27 06:36:28] mak77@anvi.it
no that is my writing fault on this submission :)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/21885
--
Edit this bug report at http://bugs.php.net/?id=21885&edit=1