note 26694 added to features.remote-files
| From: | vlad at vkelman dot com | Date: | Sat, 09 Nov 2002 07:37:41 +0000 |
| Subject: | note 26694 added to features.remote-files | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-39212@lists.php.net to get a copy of this message | ||
There is a good news for klaus at netlibrary dot de and others: PHP 4.2.3. DOES block
include('some_html_file'). It doesn't matter if this file has actual PHP inside or
not: include() doesn't work. You can use fopen() or readfile(), but this means, the content
won't be executed and therefore no more vulnerability exists.
--
http://www.php.net/manual/en/features.remote-files.php
http://master.php.net/manage/user-notes.php?action=edit+26694
http://master.php.net/manage/user-notes.php?action=delete+26694
http://master.php.net/manage/user-notes.php?action=reject+26694