note 23244 added to function.include

From: Date: Fri, 12 Jul 2002 15:04:53 +0000
Subject: note 23244 added to function.include
Groups: php.notes 
Request: Send a blank email to php-notes+get-32987@lists.php.net to get a copy of this message
An important include tip: include() will (now?) follow relative paths, no matter where you put them, so be very careful with it. For example: include('/blah/blah/$foo'); Is very, very bad, because if someone gets nasty and adds '?foo=../../../../../etc/passwd' to the URL it will work. (tested on 4.2.1/apache) If you need to do this, one idea is to do a !strsr($foo,'../') to make sure no one's trying anything funny, or find another solution. Not much of a threat if you are setup properly - just something to note. -- http://www.php.net/manual/en/function.include.php http://master.php.net/manage/user-notes.php?action=edit+23244 http://master.php.net/manage/user-notes.php?action=delete+23244 http://master.php.net/manage/user-notes.php?action=reject+23244

« previous php.notes (#32987) next »