Re: [RFC] Script only include/require
| From: | Stanislav Malyshev | Date: | Wed, 25 Feb 2015 04:57:44 +0000 |
| Subject: | Re: [RFC] Script only include/require | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-83739@lists.php.net to get a copy of this message | ||
Hi!
> I have to at least php://
> php://input or php://stdin
> allows attacker script execution via POST if it's allowed
> by allow_url_include=On.
allow_url_include=On means it's allowed. That's what "on" setting is
for. Production setting should always be "off".
--
Stas Malyshev
smalyshev@gmail.com