allow_url_fopen ini directive not enough

From: Date: Thu, 09 Dec 2004 10:03:20 +0000
Subject: allow_url_fopen ini directive not enough
Groups: php.internals 
Request: Send a blank email to internals+get-14033@lists.php.net to get a copy of this message
Hi, I would like to see a new directive to go alongside "allow_url_fopen" to allow people to turn on or off the ability to include/require a remote file. The ability to include and execute a file as php from a remote host leaves many applications open to cross-site-scripting attacks. This would be easily avoidable if we had a directive (allow_url_include?) that by default removed this capability. Any thoughts? KJ

« previous php.internals (#14033) next »