File inclusion path manipulation

File inclusion path manipulation

Description

Using unvalidated input as an include or require path may expose files or execute unintended PHP code. The files that can be included and the impact depend on file permissions, remote inclusion settings and other configuration.

Potential impact

Sensitive files may be exposed, authentication may be bypassed, or unintended PHP code may run.

Remediation

Fix includable files in a key-based allow-list. Do not use input directly as a path string.

Examples

Before

php
<?php
$file = $_GET['page'];
include($file);

After

php
<?php
$pages = [
    'home' => __DIR__ . '/pages/home.php',
    'help' => __DIR__ . '/pages/help.php',
];

$page = $_GET['page'] ?? 'home';
if (!isset($pages[$page])) {
    http_response_code(404);
    exit;
}

include $pages[$page];

Explanation:

  • Before: User-controlled data reaches include or require, potentially exposing local files or executing unintended PHP code.
  • After: Maps permitted keys to fixed files instead of using user input as a path.

References