PHP File Inclusion

Revision as of 10:19, 18 October 2008

This is a Vulnerability.

This article is a stub. You can help OWASP by expanding it or discussing it on its Talk page.

Last revision (mm/dd/yy): 10/18/2008

PHP as many other languages allow the inclution of files in order to provide or extend the functionality of the current file.

<?PHP include '/path/filename.php'; include_once 'path/filename.class.php'; require '../path/'; require_once ''; ?>

  • Remote file inclusion using variables from the request POST or GET

