opendir security hole

From: Date: Thu, 23 May 2002 13:22:28 +0000
Subject: opendir security hole
Groups: php.general 
Request: Send a blank email to php-general+get-98906@lists.php.net to get a copy of this message
hi i am creating a webbased filemanager for uploading files to the database, to determin which dir i upload to i have the directory in the query string ie ?dir=blah , i have found a security flaw where if you type dir=../../../../ it will show you the root dir of the server , how can i lock into a directory when using opendir ? please let me know thanks

« previous php.general (#98906) next »