Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7563229
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 30, 20262026-05-30T13:36:44+00:00 2026-05-30T13:36:44+00:00

I have a php script in a folder (I call it the root folder).

  • 0

I have a php script in a folder (I call it the root folder). The script can basically list all files in subfolders of this root folder. The user can specify which subfolder should be displayed by using GET-parameters.

script.php?foo

would display the content of

<root folder>/foo/

and
script.php?.bar
would display the content of

<root folder>/.bar/

However, users could also “cheat” and use commands like /.. to display the content of folders they souldn’t be able to see.

For example with

script.php?/../..

the users could get very high in the folder hierarchy.

Do you have an idea how to prevent users of doing “cheats” like this.

For reason of simplicity, let’s say the GET-parameter is stored in $searchStatement.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-30T13:36:45+00:00Added an answer on May 30, 2026 at 1:36 pm

    You could use realpath to resolve the relative path to an absolute one and then check if that path begins with your “root” folder’s path:

    $absolutePath = realpath(__DIR__ . '/' . trim($searchStatement, '/'));
    
    if (strpos($absolutePath, __DIR__ .'/') !== 0) {
        die('Access denied.');
    }
    
    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have php code for list all .swf files in a folder. (The name
I have a PHP script located in my Wordpress installation's root folder wordpress-root/includes/login.php When
Using Jquery Ajax i have an entry script index.php This script lets the user
I have a php script that steps through a folder containing tab delimited files,
I have a php script $filelist = scandir('myfolder/') which list outs files from my
I have a PHP script that moves files out of a specific folder on
I have a PHP script that initialises an image gallery. It loops through all
I have a PHP script that can encode a PNG image to a Base64
I have a PHP url shortener script that redirects the user from a URL
I have a php script which uploads images to a temporary folder on the

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.