#38245 [Fbk->Opn]: File Upload Problem When magic_quotes_gpc = On

From: Date: Fri, 28 Jul 2006 21:42:14 +0000
Subject: #38245 [Fbk->Opn]: File Upload Problem When magic_quotes_gpc = On
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-100044@lists.php.net to get a copy of this message
ID: 38245 User updated by: david at orangegateos dot com Reported By: david at orangegateos dot com -Status: Feedback +Status: Open Bug Type: Scripting Engine problem Operating System: Windows 2003 and IIS6.0 PHP Version: 5CVS-2006-07-28 (snap) New Comment: I have just tried the linked version for Windows, and I continue to receive the same problem. I used the included php.ini-dist file, unmodified from the zip file. However, I do receive the full, escaped filename with 5.0.2, similiar to what you say you receive with the linked 5.2. This is on a Windows Server 2003 box with IIS6.0. Previous Comments: ------------------------------------------------------------------------ [2006-07-28 21:05:46] iliaa@php.net Please try using this CVS snapshot: http://snaps.php.net/php5.2-latest.tar.gz For Windows: http://snaps.php.net/win32/php5.2-win32-latest.zip I've tried it on latest version of PHP 5.2 from CVS and it works fine, the full, escaped file name is returned. ------------------------------------------------------------------------ [2006-07-28 20:39:45] david at orangegateos dot com Description: ------------ This problem seems to be related to an older occurrence of the bug found at http://bugs.php.net/bug.php?id=31398. The full filename is not passed to the $_FILES[] array when submitting a file with an apostrophe in the name. For example: David's Image.jpg When uploading this file, everything before and including the apostrophe is removed so that the following will only show: s Image.jpg. The problem occurs when I am using $_FILES['userfile']['name'] to retrieve the original filename. I tried today’s CVS, upgrading from 5.1.4. Also, I have tried PHP 4.4.2 on Windows, and the problem occurs there as well, but not on a Linux system. As was suggested in the previous bug report, I tried 5.0.2 and this bug is not reproducible. Reproduce code: --------------- <?php echo '<h1>' . $_FILES['userfile']['name'] . '</h1>'; ?> <form name="fileUpload" enctype="multipart/form-data" method="post" action="index.php"> <input type="hidden" name="MAX_FILE_SIZE" value="2000000" /> <input type="file" name="userfile" value="" /><br /> <br /> <input type="submit" name="submit" value="Upload File" /> </form> Expected result: ---------------- The full name of the file, including the apostrophe: David's Image.jpg. Actual result: -------------- The first part of the filename is removed, including the apostrophe. Displays: s Image.jpg. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=38245&edit=1

« previous php.bugs (#100044) next »