php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #4367 read source code of ANY file on the server
Submitted: 2000-05-09 21:24 UTC Modified: 2000-05-21 17:12 UTC
From: alex at twoteeth dot net Assigned:
Status: Closed Package: Other
PHP Version: 3.0.16 OS: FreeBSD 3.4-RELEASE
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: alex at twoteeth dot net
New email:
PHP Version: OS:

 

 [2000-05-09 21:24 UTC] alex at twoteeth dot net
ok mysql.php3 is in /home/httpd/htdocs/
and show_source.php3 is in /home/mystik/public_html/
here's a sample script that the user "mystik" created:
<?
print("<pre>");
system("cat /home/httpd/htdocs/mysql.php3");
print("</pre>");
?>

Obviously you can see what that does. Is there a way to configure apache or the php3.ini file to make it impossible for the user to access that specific file ?
I read the security section in the manual and i saw something about user_dir and doc_root. It's not too clear on how to set the, etc.
Please look into this.
Regards

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2000-05-21 17:12 UTC] jimw at cvs dot php dot net
read up on safe_mode.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sat Oct 10 20:00:02 2026 UTC