[BlueOnyx:08193] Re: open_basedir bug in the SuPHP

Jason Ozin bluequartz at ozin.com
Mon Aug 22 19:55:26 -05 2011


Jeff said:

Add /home/ to the global open_basedir field in php settings (so it reads - /tmp/:/var/lib/php/session/:/home/). I had the same problem with my 5107R install.

Thanks for confirming the bug Jeff but that is horrible fix Jeff as it opens up quite a bit of a security hole.

I wonder if the bug is due to the "." in ".sites" breaking the string?

Michael can you confirm this major bug please and suggest a fix?

Jason
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.blueonyx.it/pipermail/blueonyx/attachments/20110823/f7d0cbf3/attachment.html>


More information about the Blueonyx mailing list