note 28472 deleted from features.remote-files by nlopess
| From: | nlopess@php.net | Date: | Wed, 16 Mar 2005 15:15:04 +0000 |
| Subject: | note 28472 deleted from features.remote-files by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-86555@lists.php.net to get a copy of this message | ||
Note Submitter: robro at compsoc dot nuigalway dot ie dot nospam
----
The easiest way I'd see around the security hold mentioned above would be to turn off
allow_url_fopen, using ini_set.
If that is not acceptable you can simply str_replace out the :// part that seperates the protocol
from the address.
<?php
include( str_replace("://", "", $whatever) );
?>
should do the trick.