Ask a Question related to PHP Bugs, Design and Development.
-
florin at flachi dot net #1
#40651 [NEW]: Remote file inclusion
From: florin at flachi dot net
Operating system: Irrelevent
PHP version: 5.2.1
PHP Bug Type: Feature/Change Request
Bug description: Remote file inclusion
Description:
------------
Many webhosting companies and not only have a lot of problems because of
the ability of users to include remote files. This can be stopped by
disabling allow_url_fopen but that will also stop to fopen () remote
files. This is widely used by a lot of scripts and users get angry all the
time if we disable allow_url_fopen.
All these things can be solved by creating an option in php.ini to allow
administrators to disable users to include remote files. Thank you.
--
Edit bug report at [url]http://bugs.php.net/?id=40651&edit=1[/url]
--
Try a CVS snapshot (PHP 4.4): [url]http://bugs.php.net/fix.php?id=40651&r=trysnapshot44[/url]
Try a CVS snapshot (PHP 5.2): [url]http://bugs.php.net/fix.php?id=40651&r=trysnapshot52[/url]
Try a CVS snapshot (PHP 6.0): [url]http://bugs.php.net/fix.php?id=40651&r=trysnapshot60[/url]
Fixed in CVS: [url]http://bugs.php.net/fix.php?id=40651&r=fixedcvs[/url]
Fixed in release: [url]http://bugs.php.net/fix.php?id=40651&r=alreadyfixed[/url]
Need backtrace: [url]http://bugs.php.net/fix.php?id=40651&r=needtrace[/url]
Need Reproduce Script: [url]http://bugs.php.net/fix.php?id=40651&r=needscript[/url]
Try newer version: [url]http://bugs.php.net/fix.php?id=40651&r=oldversion[/url]
Not developer issue: [url]http://bugs.php.net/fix.php?id=40651&r=support[/url]
Expected behavior: [url]http://bugs.php.net/fix.php?id=40651&r=notwrong[/url]
Not enough info: [url]http://bugs.php.net/fix.php?id=40651&r=notenoughinfo[/url]
Submitted twice: [url]http://bugs.php.net/fix.php?id=40651&r=submittedtwice[/url]
register_globals: [url]http://bugs.php.net/fix.php?id=40651&r=globals[/url]
PHP 3 support discontinued: [url]http://bugs.php.net/fix.php?id=40651&r=php3[/url]
Daylight Savings: [url]http://bugs.php.net/fix.php?id=40651&r=dst[/url]
IIS Stability: [url]http://bugs.php.net/fix.php?id=40651&r=isapi[/url]
Install GNU Sed: [url]http://bugs.php.net/fix.php?id=40651&r=gnused[/url]
Floating point limitations: [url]http://bugs.php.net/fix.php?id=40651&r=float[/url]
No Zend Extensions: [url]http://bugs.php.net/fix.php?id=40651&r=nozend[/url]
MySQL Configuration Error: [url]http://bugs.php.net/fix.php?id=40651&r=mysqlcfg[/url]
florin at flachi dot net Guest
-
Remote.pm (File::Remote) problem
I've got a very simple script (see below) that uses the File::Remote module. I've set up the script to use ssh/scp and there is no problem for the... -
[#21740592] Inclusion in Google index
Greetings, Thank you for contacting Google. Google is currently blocked from crawling your site by the robots.txt file that your server uses... -
Inclusion Weirdness
Hey There, I am having I weird problem with using PHP::DB. I have an OO model whereby I load objects and they know how to persist and load... -
Non-Core Module Inclusion
On 24 Jul 2003 19:03:46 -0700, Jeff Mott <mjeff1@twcny.rr.com> wrote: It's easiest if you just tell the users which modules they need to... -
Header Inclusion style
If I include the headers(.h files) like #include "myHeader.h", in my implementation file(.C file), then 'myHeader.h' is properly included. But,... -
derick@php.net #2
#40651 [Opn->Csd]: Remote file inclusion
ID: 40651
Updated by: [email]derick@php.net[/email]
Reported By: florin at flachi dot net
-Status: Open
+Status: Closed
Bug Type: Feature/Change Request
Operating System: Irrelevent
PHP Version: 5.2.1
New Comment:
We already have this:
[url]http://no.php.net/manual/en/ref.filesystem.php#ini.allow-url-include[/url]
Previous Comments:
------------------------------------------------------------------------
[2007-02-27 00:40:42] florin at flachi dot net
Description:
------------
Many webhosting companies and not only have a lot of problems because
of the ability of users to include remote files. This can be stopped by
disabling allow_url_fopen but that will also stop to fopen () remote
files. This is widely used by a lot of scripts and users get angry all
the time if we disable allow_url_fopen.
All these things can be solved by creating an option in php.ini to
allow administrators to disable users to include remote files. Thank
you.
------------------------------------------------------------------------
--
Edit this bug report at [url]http://bugs.php.net/?id=40651&edit=1[/url]
derick@php.net Guest



Reply With Quote

