note 23244 added to function.include
| From: | php at chaosgfx dot com | Date: | Fri, 12 Jul 2002 15:04:53 +0000 |
| Subject: | note 23244 added to function.include | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-32987@lists.php.net to get a copy of this message | ||
An important include tip:
include() will (now?) follow relative paths, no matter where you put them, so be very careful with
it.
For example:
include('/blah/blah/$foo');
Is very, very bad, because if someone gets nasty and adds '?foo=../../../../../etc/passwd'
to the URL it will work. (tested on 4.2.1/apache)
If you need to do this, one idea is to do a !strsr($foo,'../') to make sure no one's
trying anything funny, or find another solution.
Not much of a threat if you are setup properly - just something to note.
--
http://www.php.net/manual/en/function.include.php
http://master.php.net/manage/user-notes.php?action=edit+23244
http://master.php.net/manage/user-notes.php?action=delete+23244
http://master.php.net/manage/user-notes.php?action=reject+23244