Bug #49683 [Nab->Dup]: $_FILES overwrite

From: Date: Sun, 07 Aug 2016 18:05:23 +0000
Subject: Bug #49683 [Nab->Dup]: $_FILES overwrite
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203045@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=49683&edit=1

 ID:                 49683
 Updated by:         cmb@php.net
 Reported by:        adamiwaniuk at gmail dot com
 Summary:            $_FILES overwrite
-Status:             Not a bug
+Status:             Duplicate
 Type:               Bug
 Package:            *General Issues
 PHP Version:        5.2.11
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

> Same problem as already reported in bug #48597

So this is a duplicate.


Previous Comments:
------------------------------------------------------------------------
[2009-09-27 02:52:39] jani@php.net

Same problem as already reported in bug #48597

------------------------------------------------------------------------
[2009-09-26 21:47:06] adamiwaniuk at gmail dot com

Description:
------------
When 'name' from Content-Disposition ends with '[' or '[xxxxx' it is
possible to prepeare some fake data of $_FILES structure aray
If someone upload multiple files it is possible to set fake size of file, or when someone is using
unsafe method upload (without is_uploaded_file()/move_uploaded_file()) to set tmp_name to any file

example content:

Content-Disposition: form-data; name="images[[tmp_name]"; filename="file.txt"

Content-Disposition: form-data; name="images[tmp_name]["; filename="index.php"

Reproduce code:
---------------
<?php var_dump($_FILES)?>

<?php

foreach ($_FILES["images"]["tmp_name"] as $key => $name){
	copy($_FILES["images"]["tmp_name"][$key],'upload\\a'.rand().'.txt');
}
?>


<?php
foreach ($_FILES["images"]["tmp_name"] as $key => $name) {
	if ($_FILES["images"]["size"][$key]>0 &&
$_FILES["images"]["size"][$key]<1024)
		move_uploaded_file($_FILES["images"]["tmp_name"][$key],'upload\\'.rand().'.txt');
}

?>


Expected result:
----------------
it should skip upload file when 'name' ends with [ or '[xxx'

Actual result:
--------------
array(1) {
  ["images"]=>
  array(5) {
    ["name"]=>
    array(1) {
      ["[tmp_name"]=>
      string(5) "file.txt"
    }
    ["type"]=>
    array(1) {
      ["[tmp_name"]=>
      string(10) "text/plain"
    }
    ["tmp_name"]=>
    array(5) {
      ["[tmp_name"]=>
      string(66) "C:\Documents and Settings\Adam\Ustawienia lokalne\Temp\php36E3.tmp"
      ["[name"]=>
      string(10) "index.php"
      ["[type"]=>
      string(10) "text/plain"
      ["[error"]=>
      int(0)
      ["[size"]=>
      int(11)
    }
    ["error"]=>
    array(1) {
      ["[tmp_name"]=>
      int(0)
    }
    ["size"]=>
    array(1) {
      ["[tmp_name"]=>
      int(3)
    }
  }
}


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=49683&edit=1


Thread (3 messages)

« previous php.bugs (#203045) next »