Page 2 of 2 FirstFirst 12
Results 11 to 15 of 15

Thread: [PHP] Includes.

  1. #11
    Join Date
    Aug 2004
    Location
    UK
    Posts
    11,283
    Tokens
    2,031

    Latest Awards:

    Default

    Quote Originally Posted by Invent View Post
    Yes, but I thought incase for some odd reason they may want to protect files from another folder being accessed.

    Because with your script the user could do ?page=../../page.php

    Not sure why you need to block it but yeah
    What your suggestion wouldnt work since the dir is hard coded. ?page=../../page would be opening

    pagesfolder/../../page.php, and to my knowlage the ../../ doesn't work unless its at the beginning to the directory name?

    Although it does allow you to open a subdirectry within your pages directory should you want to.

  2. #12
    Join Date
    May 2005
    Location
    San Francisco, CA
    Posts
    7,160
    Tokens
    2,331

    Latest Awards:

    Default

    pagesfolder/../../page.php would open the file page.php 2 folders below pagesfolder I'm pretty sure.

  3. #13
    Join Date
    Sep 2006
    Posts
    2,114
    Tokens
    0

    Latest Awards:

    Default

    Erm.. Isn't this going a bit of topic lol.
    Looking for a good desiner to design a social networking template.

    PM me.

  4. #14
    Join Date
    Aug 2004
    Location
    UK
    Posts
    11,283
    Tokens
    2,031

    Latest Awards:

    Default

    Quote Originally Posted by Invent View Post
    pagesfolder/../../page.php would open the file page.php 2 folders below pagesfolder I'm pretty sure.
    Just created a test script in my testing server. I want able to get it to open a page outside the dir by adding in ../../ "/

    * scratch that, yes i was. Dang. Could make it work by createing a custom page extention though, which wouldnt be used outside the dir (or just filtering../../
    Last edited by Mentor; 19-06-2007 at 07:40 PM.

  5. #15
    Join Date
    May 2005
    Location
    San Francisco, CA
    Posts
    7,160
    Tokens
    2,331

    Latest Awards:

    Default

    just filter "." it's not needed whatsoever

Page 2 of 2 FirstFirst 12

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •