RE: [PHP] opendir security hole

From: Date: Thu, 23 May 2002 15:32:05 +0000
Subject: RE: [PHP] opendir security hole
Groups: php.general 
Request: Send a blank email to php-general+get-98933@lists.php.net to get a copy of this message
Use: http://us2.php.net/manual/en/configuration.php#ini.open-basedir It's also a good idea to always validate the data that comes from the user, especially when dealing with file related functions. Randy -----Original Message----- From: daniel [mailto:daniel@electroteque.org] Sent: Thursday, May 23, 2002 9:22 AM To: php-general@lists.php.net Subject: [PHP] opendir security hole hi i am creating a webbased filemanager for uploading files to the database, to determin which dir i upload to i have the directory in the query string ie ?dir=blah , i have found a security flaw where if you type dir=../../../../ it will show you the root dir of the server , how can i lock into a directory when using opendir ? please let me know thanks -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php

« previous php.general (#98933) next »