Sanitize file path in PHP

后端 未结 7 1073
夕颜
夕颜 2020-12-01 11:00

Greetings, I\'m hoping to make my tiny program secure so that potential malicious users cannot view sensitive files on the server.

    $path = \"/home/gsmcm         


        
7条回答
  •  鱼传尺愫
    2020-12-01 11:14

    If you can, use a whitelist like an array of allowed files and check the input against that: if the file asked by the user isn't present in that list, deny the request.

提交回复
热议问题