note 37761 modified in function.fopen by danbrown

From: Date: Mon, 08 Jun 2009 23:44:22 +0000
Subject: note 37761 modified in function.fopen by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-156569@lists.php.net to get a copy of this message
PHP will open a directory if a path with no file name is supplied. This just bit me. I was not checking the filename part of a concatenated string. For example: <?php $fd = fopen('/home/mydir/' . $somefile, 'r'); ?> Will open the directory if $somefile = '' If you attempt to read using the file handle you will get the binary directory contents. I tried append mode and it errors out so does not seem to be dangerous. This is with FreeBSD 4.5 and PHP 4.3.1. Behaves the same on 4.1.1 and PHP 4.1.2. I have not tested other version/os combinations. --was-- PHP will open a directory if a path with no file name is supplied. This just bit me. I was not checking the filename part of a concatenated string. For example: $fd = fopen('/home/mydir/' . $somefile, 'r'); Will open the directory if $somefile = '' If you attempt to read using the file handle you will get the binary directory contents. I tried append mode and it errors out so does not seem to be dangerous. This is with FreeBSD 4.5 and PHP 4.3.1. Behaves the same on 4.1.1 and PHP 4.1.2. I have not tested other version/os combinations. http://php.net/manual/en/function.fopen.php

« previous php.notes (#156569) next »