note 37761 added to function.fopen
| From: | kendotgreggatrwredotcom at rn2 dot php dot net | Date: | Tue, 25 Nov 2003 20:03:49 +0000 |
| Subject: | note 37761 added to function.fopen | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-60983@lists.php.net to get a copy of this message | ||
PHP will open a directory if a path with no file name is supplied. This just bit me. I was not
checking the filename part of a concatenated string.
For example:
$fd = fopen('/home/mydir/' . $somefile, 'r');
Will open the directory if $somefile = ''
If you attempt to read using the file handle you will get the binary directory contents. I tried
append mode and it errors out so does not seem to be dangerous.
This is with FreeBSD 4.5 and PHP 4.3.1. Behaves the same on 4.1.1 and PHP 4.1.2. I have not tested
other version/os combinations.
----
Manual Page -- http://www.php.net/manual/en/function.fopen.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+37761
Delete -- http://master.php.net/manage/user-notes.php?action=delete+37761&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+37761&report=yes
Search -- http://master.php.net/manage/user-notes.php