|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
[2000-05-21 17:12 UTC] jimw at cvs dot php dot net
|
|||||||||||||||||||||||||||
Copyright © 2001-2026 The PHP GroupAll rights reserved. |
Last updated: Sat Oct 10 19:00:01 2026 UTC |
ok mysql.php3 is in /home/httpd/htdocs/ and show_source.php3 is in /home/mystik/public_html/ here's a sample script that the user "mystik" created: <? print("<pre>"); system("cat /home/httpd/htdocs/mysql.php3"); print("</pre>"); ?> Obviously you can see what that does. Is there a way to configure apache or the php3.ini file to make it impossible for the user to access that specific file ? I read the security section in the manual and i saw something about user_dir and doc_root. It's not too clear on how to set the, etc. Please look into this. Regards