|
Posted by R K on 10/25/06 14:19
If uploading enabled, file permissions can't stop a user from
uploading a file, say "hole.php", then executing that file with the
URL http://host/uploaddir/hole.php. All PHP files just have rw or just
r permissions and they are still executed by the server. Seems like a
PHP issue. Are we leaving this up to developers to take care not to
create this hole?
BTW, how do I fix this in an administrative way?
Thx
-R
Navigation:
[Reply to this message]
|