| Anonymous | Login | Signup for a new account | 06-10-2026 07:15 PDT |
| Main | My View | View Issues | Change Log | Docs |
| Viewing Issue Simple Details [ Jump to Notes ] | [ View Advanced ] [ Issue History ] [ Print ] | ||||||||
| ID | Category | Severity | Reproducibility | Date Submitted | Last Update | ||||
| 0004005 | [Quercus] | major | always | 04-20-10 00:31 | 12-10-12 14:34 | ||||
| Reporter | hm2k | View Status | public | ||||||
| Assigned To | nam | ||||||||
| Priority | normal | Resolution | fixed | ||||||
| Status | closed | Product Version | |||||||
| Summary | 0004005: php.ini disable_functions does not work | ||||||||
| Description |
phpinfo() reports that my php.ini is .../WEB-INF/php.ini I know the php.ini is being used as other options are being set. But the following does not work: disable_functions = "dl,highlight_file" As I am unable to disable these functions (and others), it poses a security risk and as such this bug is considered of high importance. |
||||||||
| Additional Information | |||||||||
| Attached Files | |||||||||
|
|
|||||||||
Notes |
|
|
(0005236) dicr 05-11-11 15:24 |
I think this can be implemented by native java security managers. Please, search "quercus serurity manager". http://www.caucho.com/resin-3.0/security/securitymanager.xtp [^] |
|
(0006111) nam 12-10-12 14:34 |
Fixed for 4.0.33. disable_functions need to be set in php.ini. |
|
(0006112) nam 12-10-12 14:34 |
php/1004 php/1005 php/1006 |
| Mantis 1.0.0rc3[^]
Copyright © 2000 - 2005 Mantis Group
34 total queries executed. 29 unique queries executed. |