allow_url_fopen ini directive not enough
| From: | KJ | Date: | Thu, 09 Dec 2004 10:03:20 +0000 |
| Subject: | allow_url_fopen ini directive not enough | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-14033@lists.php.net to get a copy of this message | ||
Hi,
I would like to see a new directive to go alongside "allow_url_fopen" to
allow people to turn on or off the ability to include/require a remote file.
The ability to include and execute a file as php from a remote host
leaves many applications open to cross-site-scripting attacks.
This would be easily avoidable if we had a directive
(allow_url_include?) that by default removed this capability.
Any thoughts?
KJ