Bug #18581: Uploaded Files Incorrectly assumed to exist
| From: | alexis at mvs dot com | Date: | Fri, 26 Jul 2002 02:41:45 +0000 |
| Subject: | Bug #18581: Uploaded Files Incorrectly assumed to exist | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-15257@lists.php.net to get a copy of this message | ||
From: alexis@mvs.com
Operating system: Solaris 7 / RH Linux 7.3
PHP version: 4.2.2
PHP Bug Type: *General Issues
Bug description: Uploaded Files Incorrectly assumed to exist
In previous versions of PHP (before 4.2.2) when a form was submited
containing an <input type="file"> field, if the browsed file size was 0 or
if the file specified in the field didn't exist on the submitter's disk,
the file name was reported "none" and no temporary file was created on the
Server.
I tried this with the following script in PHP 4.1.2 and PHP 4.2.2 both
running in Solaris 7 Boxes with Apache 1.3 The file name of the script is
"file_problem.php".
<?
if ($_REQUEST["answered"] == "ok") {
echo "<pre>";
echo $_SERVER["SERVER_SOFTWARE"] . "\n\n";
echo "These are the contents of the \$_FILES array :: \n";
print_r($_FILES);
echo "</pre>";
} else {
?>
<form name="forma" action="file_problem.php" method="post"
ENCTYPE="multipart/form-data">
<input type="file" name="userfile">
<input type="hidden" name="answered" value="ok">
<input type="submit">
</form>
<?}?>
***** When we click on the browse button and select a file from our
localdisk this is returned in PHP 4.2.2 :
Apache/1.3.26 (Unix) PHP/4.2.2
These are the contents of the $_FILES array ::
Array
(
[userfile] => Array
(
[name] => fetuccinni.jpg
[type] => image/pjpeg
[tmp_name] => /var/tmp/phpHaaagK
[error] => 0
[size] => 12385
)
)
***** Looks somewhat different to PHP 4.1.2 because of the "error" field
but works fine.
Apache/1.3.24 (Unix) PHP/4.1.2
These are the contents of the $_FILES array ::
Array
(
[userfile] => Array
(
[name] => ellago.jpg
[type] => image/pjpeg
[tmp_name] => /var/tmp/phpenaW3e
[size] => 10443
)
)
**** When we browse a 0 byte file or type in a bogus file name in the
field these are the different results:
Apache/1.3.26 (Unix) PHP/4.2.2
These are the contents of the $_FILES array ::
Array
(
[userfile] => Array
(
[name] => typedtext
[type] => application/octet-stream
[tmp_name] => /var/tmp/phpmxaqgK
[error] => 0
[size] => 0
)
)
Apache/1.3.24 (Unix) PHP/4.1.2
These are the contents of the $_FILES array ::
Array
(
[userfile] => Array
(
[name] => typedtext
[type] => application/octet-stream
[tmp_name] => none
[size] => 0
)
)
This is incorrect because PHP assumes the file exists and creates a file
in the server. The only way we have to determine if we have to move the
file or not is the "size" field, but there is no a way to determine if the
user really uploaded a 0 byte file or simply if the file didn't existed in
the user disk.
--
Edit bug report at http://bugs.php.net/?id=18581&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=18581&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=18581&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=18581&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=18581&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=18581&r=support
Expected behavior: http://bugs.php.net/fix.php?id=18581&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=18581&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=18581&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=18581&r=globals