note 26694 deleted from features.remote-files by vincent
| From: | vincent@php.net | Date: | Fri, 12 Sep 2003 13:21:38 +0000 |
| Subject: | note 26694 deleted from features.remote-files by vincent | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-56390@lists.php.net to get a copy of this message | ||
Note Submitter: vlad@vkelman.com
----
There is a good news for klaus at netlibrary dot de and others: PHP 4.2.3. DOES block
include('some_html_file'). It doesn't matter if this file has actual PHP inside or
not: include() doesn't work. You can use fopen() or readfile(), but this means, the content
won't be executed and therefore no more vulnerability exists.