in reply to Re: issues displaying cgi script source?
in thread issues displaying cgi script source?
Not to mention the hard coded variable of $path which is not changeable by the user and is the entire first portion of the variable $full's value.
If there is a way to break out of this directory with the current state of this script please be specific because I do not see it.
I have read about the two and three arg open calls but do not see in this implementation how a three arg open call will help any. Now I am not saying it won't because I am the farthest thing from an expert but if it will please again be more specific.
Edit: Ohh wait a minute! Oh crap I see it and tested it and yes you are correct. Big oversight on my part. Thanks for the heads up! Permissions do save me on privilaged files but there are some un-privilaged files Apache can read that people have no buisness looking at and can lead to further exploitation.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^3: issues displaying cgi script source?
by diotalevi (Canon) on Jul 06, 2004 at 22:14 UTC |