#38245 [Fbk->Opn]: File Upload Problem When magic_quotes_gpc = On
| From: | david at orangegateos dot com | Date: | Fri, 28 Jul 2006 21:42:14 +0000 |
| Subject: | #38245 [Fbk->Opn]: File Upload Problem When magic_quotes_gpc = On | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-100044@lists.php.net to get a copy of this message | ||
ID: 38245
User updated by: david at orangegateos dot com
Reported By: david at orangegateos dot com
-Status: Feedback
+Status: Open
Bug Type: Scripting Engine problem
Operating System: Windows 2003 and IIS6.0
PHP Version: 5CVS-2006-07-28 (snap)
New Comment:
I have just tried the linked version for Windows, and I continue to
receive the same problem. I used the included php.ini-dist file,
unmodified from the zip file.
However, I do receive the full, escaped filename with 5.0.2, similiar
to what you say you receive with the linked 5.2.
This is on a Windows Server 2003 box with IIS6.0.
Previous Comments:
------------------------------------------------------------------------
[2006-07-28 21:05:46] iliaa@php.net
Please try using this CVS snapshot:
http://snaps.php.net/php5.2-latest.tar.gz
For Windows:
http://snaps.php.net/win32/php5.2-win32-latest.zip
I've tried it on latest version of PHP 5.2 from CVS and it
works fine, the full, escaped file name is returned.
------------------------------------------------------------------------
[2006-07-28 20:39:45] david at orangegateos dot com
Description:
------------
This problem seems to be related to an older occurrence of the bug
found at http://bugs.php.net/bug.php?id=31398.
The full filename is not passed to the $_FILES[] array when submitting
a file with an apostrophe in the name.
For example: David's Image.jpg
When uploading this file, everything before and including the
apostrophe is removed so that the following will only show: s
Image.jpg.
The problem occurs when I am using $_FILES['userfile']['name'] to
retrieve the original filename.
I tried todays CVS, upgrading from 5.1.4. Also, I have tried PHP
4.4.2 on Windows, and the problem occurs there as well, but not on a
Linux system. As was suggested in the previous bug report, I tried
5.0.2 and this bug is not reproducible.
Reproduce code:
---------------
<?php echo '<h1>' . $_FILES['userfile']['name'] .
'</h1>'; ?>
<form name="fileUpload" enctype="multipart/form-data" method="post"
action="index.php">
<input type="hidden" name="MAX_FILE_SIZE" value="2000000" />
<input type="file" name="userfile" value="" /><br />
<br />
<input type="submit" name="submit" value="Upload File" />
</form>
Expected result:
----------------
The full name of the file, including the apostrophe: David's
Image.jpg.
Actual result:
--------------
The first part of the filename is removed, including the apostrophe.
Displays: s Image.jpg.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=38245&edit=1