Re: allow_url_fopen should be INI_ALL

From: Date: Wed, 29 Jun 2005 05:50:59 +0000
Subject: Re: allow_url_fopen should be INI_ALL
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-16989@lists.php.net to get a copy of this message
Olivier Hill writes: > Are you suggesting that someone could wipe out your entire machine by > passing a remote script that would system('rm -rf /');? It would "only" delete every file owned by the user that the webserver runs as. On my server, that's 1846 files, some of which I'm fairly attached to. > There is no problems with the include() statement. The only thing > missing, is a <blink> tag in the docs ;) If there were no problems, then why would a <blink> tag be needed? -- --My blog is at blog.russnelson.com | If you want to find Crynwr sells support for free software | PGPok | injustice in economic 521 Pleasant Valley Rd. | +1 315-323-1241 | affairs, look for the Potsdam, NY 13676-3213 | | hand of a legislator.

« previous php.internals (#16989) next »