note 35182 deleted from function.file-exists by sniper

From: Date: Sun, 23 Nov 2003 01:27:04 +0000
Subject: note 35182 deleted from function.file-exists by sniper
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-60834@lists.php.net to get a copy of this message
Note Submitter: andy@acomm-hosting.co.uk ---- PHP 4.3.2 on Apache 1.3.27 has some interesting effects. On all VHOSTS we use the: open_basedir .:/tmp:/usr/local/lib/php:/home/12345:/home/theirdomain.com as a security measure. All sites reside in: /home/12345 (Where 12345 is their userid), and then their domain is symlinked to it for ease of use: /home/theirdomain.com What we've found is after upgrading, whenever a user uses file_exists("/home/theirdomain.com/file.ext") If the file does NOT exist, then it generates an error like this: Warning: file_exists(): open_basedir restriction in effect. File(/home/theirdomain.com/docs/notthere.txt) is not within the allowed path(s): (.:/tmp:/usr/local/lib/php:/home/12345:/home/theirdomain.com/) in /home/12345/www/docs/test.php on line 3 To combat this, as noted elsewhere change: if (file_exists("/home/theirdomain.com/file.ext")) to if(file_exists(realpath("/home/theirdomain.com/file.ext")) Hope that saves people some hair-pulling!! -Andy

« previous php.notes (#60834) next »