Bug #50314 [Ver]: File upload problem with typo in form

From: Date: Thu, 05 Dec 2013 19:41:48 +0000
Subject: Bug #50314 [Ver]: File upload problem with typo in form
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183152@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=50314&edit=1

 ID:                 50314
 Updated by:         mike@php.net
 Reported by:        jj07020 at lanet dot lv
 Summary:            File upload problem with typo in form
 Status:             Verified
 Type:               Bug
 Package:            *General Issues
 Operating System:   Windows XP Pro SP3
 PHP Version:        5.*, 6
 Block user comment: N
 Private report:     N

 New Comment:

See bug #48597


Previous Comments:
------------------------------------------------------------------------
[2009-11-30 16:10:29] jani@php.net

This is not specific to any SAPI, happens also with sapi/cgi/ from today.

------------------------------------------------------------------------
[2009-11-29 12:38:08] jj07020 at lanet dot lv

I tried it with php 5.2 (Snapshot Fri, 27 Nov 2009 11:41:38 +0000, Version: 5.2.12RC3-dev) and it
produces the same result.

------------------------------------------------------------------------
[2009-11-27 14:20:01] jj07020 at lanet dot lv

Description:
------------
It is possible to supply a filename which will be incorrectly parsed by PHP. The problem occurs when
uploading a file from an HTML form with attributes name="file[" (lacking the closing
bracket) and type="file". I'm using Apache 2.2.14 & PHP 5.3.1, but I was able to
reproduce the bug with Apache 2.2.10 & PHP 5.3.0.


Reproduce code:
---------------
HTML form - form.html:

<form method="post" enctype="multipart/form-data"
action="upload.php">
<input type="file" name="file[" />
<input type="submit" value="OK" />
</form>


PHP code - upload.php:

<?php
var_dump($_FILES);
?>


The body of the HTTP request:

------------3PL7QzumhbsotvnG6nZnmR
Content-Disposition: form-data; name="file["; filename="code.gif"
Content-Type: image/gif

<binary gif data>

------------3PL7QzumhbsotvnG6nZnmR--


Expected result:
----------------
The array $_FILES should contain valid keys as specified in http://www.php.net/manual/en/features.file-upload.post-method.php.
Hovever, the following assertion fails:

if (isset($_FILES["file"])) {
    assert(is_string($_FILES["name"])); // actual key is "[name"
}

Since the filename ("file[") lacks the closing bracket, it probably should be interpreted
as a single file named "file[":

array(1) { ["file["]=> array(5) { ["name"]=> string(8)
"code.gif" ["type"]=> string(9) "image/gif"
["tmp_name"]=> string(17) "C:\Temp\php3A.tmp" ["error"]=> int(0)
["size"]=> int(3342) } }


Actual result:
--------------
The array $_FILES:

array(1) { ["file"]=> array(5) { ["[name"]=> string(8)
"code.gif" ["[type"]=> string(9) "image/gif"
["[tmp_name"]=> string(17) "C:\Temp\php3A.tmp" ["[error"]=>
int(0) ["[size"]=> int(3342) } }



------------------------------------------------------------------------



-- 
Edit this bug report at https://bugs.php.net/bug.php?id=50314&edit=1


Thread (6 messages)

« previous php.bugs (#183152) next »