note 27085 added to function.system
| From: | ffyk3s at home dot se | Date: | Fri, 22 Nov 2002 10:39:29 +0000 |
| Subject: | note 27085 added to function.system | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-39853@lists.php.net to get a copy of this message | ||
When having users allowed to run php scripts I found that the webserver being able to read the
home-directorys, it allows users to run commands like system("cat
/home/auser/connectdb.inc"); as the webserver, thus, all users being able to run scripts can
browse eachothers home-directories and finding database-passwords.. how do i get around this?
--
http://www.php.net/manual/en/function.system.php
http://master.php.net/manage/user-notes.php?action=edit+27085
http://master.php.net/manage/user-notes.php?action=delete+27085
http://master.php.net/manage/user-notes.php?action=reject+27085