note 27085 added to function.system

From: Date: Fri, 22 Nov 2002 10:39:29 +0000
Subject: note 27085 added to function.system
Groups: php.notes 
Request: Send a blank email to php-notes+get-39853@lists.php.net to get a copy of this message
When having users allowed to run php scripts I found that the webserver being able to read the home-directorys, it allows users to run commands like system("cat /home/auser/connectdb.inc"); as the webserver, thus, all users being able to run scripts can browse eachothers home-directories and finding database-passwords.. how do i get around this? -- http://www.php.net/manual/en/function.system.php http://master.php.net/manage/user-notes.php?action=edit+27085 http://master.php.net/manage/user-notes.php?action=delete+27085 http://master.php.net/manage/user-notes.php?action=reject+27085

« previous php.notes (#39853) next »