#40651 [NEW]: Remote file inclusion

Ask a Question related to PHP Bugs, Design and Development.

  1. #1

    Default #40651 [NEW]: Remote file inclusion

    From: florin at flachi dot net
    Operating system: Irrelevent
    PHP version: 5.2.1
    PHP Bug Type: Feature/Change Request
    Bug description: Remote file inclusion

    Description:
    ------------
    Many webhosting companies and not only have a lot of problems because of
    the ability of users to include remote files. This can be stopped by
    disabling allow_url_fopen but that will also stop to fopen () remote
    files. This is widely used by a lot of scripts and users get angry all the
    time if we disable allow_url_fopen.

    All these things can be solved by creating an option in php.ini to allow
    administrators to disable users to include remote files. Thank you.



    --
    Edit bug report at [url]http://bugs.php.net/?id=40651&edit=1[/url]
    --
    Try a CVS snapshot (PHP 4.4): [url]http://bugs.php.net/fix.php?id=40651&r=trysnapshot44[/url]
    Try a CVS snapshot (PHP 5.2): [url]http://bugs.php.net/fix.php?id=40651&r=trysnapshot52[/url]
    Try a CVS snapshot (PHP 6.0): [url]http://bugs.php.net/fix.php?id=40651&r=trysnapshot60[/url]
    Fixed in CVS: [url]http://bugs.php.net/fix.php?id=40651&r=fixedcvs[/url]
    Fixed in release: [url]http://bugs.php.net/fix.php?id=40651&r=alreadyfixed[/url]
    Need backtrace: [url]http://bugs.php.net/fix.php?id=40651&r=needtrace[/url]
    Need Reproduce Script: [url]http://bugs.php.net/fix.php?id=40651&r=needscript[/url]
    Try newer version: [url]http://bugs.php.net/fix.php?id=40651&r=oldversion[/url]
    Not developer issue: [url]http://bugs.php.net/fix.php?id=40651&r=support[/url]
    Expected behavior: [url]http://bugs.php.net/fix.php?id=40651&r=notwrong[/url]
    Not enough info: [url]http://bugs.php.net/fix.php?id=40651&r=notenoughinfo[/url]
    Submitted twice: [url]http://bugs.php.net/fix.php?id=40651&r=submittedtwice[/url]
    register_globals: [url]http://bugs.php.net/fix.php?id=40651&r=globals[/url]
    PHP 3 support discontinued: [url]http://bugs.php.net/fix.php?id=40651&r=php3[/url]
    Daylight Savings: [url]http://bugs.php.net/fix.php?id=40651&r=dst[/url]
    IIS Stability: [url]http://bugs.php.net/fix.php?id=40651&r=isapi[/url]
    Install GNU Sed: [url]http://bugs.php.net/fix.php?id=40651&r=gnused[/url]
    Floating point limitations: [url]http://bugs.php.net/fix.php?id=40651&r=float[/url]
    No Zend Extensions: [url]http://bugs.php.net/fix.php?id=40651&r=nozend[/url]
    MySQL Configuration Error: [url]http://bugs.php.net/fix.php?id=40651&r=mysqlcfg[/url]
    florin at flachi dot net Guest

  2. Similar Questions and Discussions

    1. Remote.pm (File::Remote) problem
      I've got a very simple script (see below) that uses the File::Remote module. I've set up the script to use ssh/scp and there is no problem for the...
    2. [#21740592] Inclusion in Google index
      Greetings, Thank you for contacting Google. Google is currently blocked from crawling your site by the robots.txt file that your server uses...
    3. Inclusion Weirdness
      Hey There, I am having I weird problem with using PHP::DB. I have an OO model whereby I load objects and they know how to persist and load...
    4. Non-Core Module Inclusion
      On 24 Jul 2003 19:03:46 -0700, Jeff Mott <mjeff1@twcny.rr.com> wrote: It's easiest if you just tell the users which modules they need to...
    5. Header Inclusion style
      If I include the headers(.h files) like #include "myHeader.h", in my implementation file(.C file), then 'myHeader.h' is properly included. But,...
  3. #2

    Default #40651 [Opn->Csd]: Remote file inclusion

    ID: 40651
    Updated by: [email]derick@php.net[/email]
    Reported By: florin at flachi dot net
    -Status: Open
    +Status: Closed
    Bug Type: Feature/Change Request
    Operating System: Irrelevent
    PHP Version: 5.2.1
    New Comment:

    We already have this:

    [url]http://no.php.net/manual/en/ref.filesystem.php#ini.allow-url-include[/url]


    Previous Comments:
    ------------------------------------------------------------------------

    [2007-02-27 00:40:42] florin at flachi dot net

    Description:
    ------------
    Many webhosting companies and not only have a lot of problems because
    of the ability of users to include remote files. This can be stopped by
    disabling allow_url_fopen but that will also stop to fopen () remote
    files. This is widely used by a lot of scripts and users get angry all
    the time if we disable allow_url_fopen.

    All these things can be solved by creating an option in php.ini to
    allow administrators to disable users to include remote files. Thank
    you.




    ------------------------------------------------------------------------


    --
    Edit this bug report at [url]http://bugs.php.net/?id=40651&edit=1[/url]
    derick@php.net Guest

Posting Permissions

  • You may not post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139