Re: opendir security hole
| From: | Analysis & Solutions | Date: | Thu, 23 May 2002 15:23:42 +0000 |
| Subject: | Re: opendir security hole | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-98932@lists.php.net to get a copy of this message | ||
On Thu, May 23, 2002 at 11:22:28PM +1000, daniel wrote:
> dir=../../../../ it will show you the root dir of the server , how can i
Before passing the $Dir variable to the file functions, clean it up...
$Dir = preg_replace('/..\//', '', $Dir);
--Dan
--
PHP classes that make web design easier
SQL Solution | Layout Solution | Form Solution
sqlsolution.info | layoutsolution.info | formsolution.info
T H E A N A L Y S I S A N D S O L U T I O N S C O M P A N Y
4015 7 Av #4AJ, Brooklyn NY v: 718-854-0335 f: 718-854-0409