note 37761 added to function.fopen

From: Date: Tue, 25 Nov 2003 20:03:49 +0000
Subject: note 37761 added to function.fopen
Groups: php.notes 
Request: Send a blank email to php-notes+get-60983@lists.php.net to get a copy of this message
PHP will open a directory if a path with no file name is supplied. This just bit me. I was not checking the filename part of a concatenated string. For example: $fd = fopen('/home/mydir/' . $somefile, 'r'); Will open the directory if $somefile = '' If you attempt to read using the file handle you will get the binary directory contents. I tried append mode and it errors out so does not seem to be dangerous. This is with FreeBSD 4.5 and PHP 4.3.1. Behaves the same on 4.1.1 and PHP 4.1.2. I have not tested other version/os combinations. ---- Manual Page -- http://www.php.net/manual/en/function.fopen.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+37761 Delete -- http://master.php.net/manage/user-notes.php?action=delete+37761&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+37761&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#60983) next »