Sec Bug->Bug #54326 [Opn]: Overriding $ FILES array during uploading multiple
| From: | krakjoe@php.net | Date: | Fri, 18 Nov 2016 14:32:44 +0000 |
| Subject: | Sec Bug->Bug #54326 [Opn]: Overriding $ FILES array during uploading multiple | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-205455@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=54326&edit=1
ID: 54326
Updated by: krakjoe@php.net
Reported by: pajoye@php.net
Summary: Overriding $ FILES array during uploading multiple
Status: Open
-Type: Security
+Type: Bug
Package: Scripting Engine problem
PHP Version: Irrelevant
Block user comment: N
Private report: Y
CVE-ID: 2011-117
New Comment:
This issue does not meet the criteria to be considered a security issue.
Please review: https://wiki.php.net/security
Previous Comments:
------------------------------------------------------------------------
[2014-02-12 18:44:46] tyrael@php.net
The CVE-ID seems to be bogus, and this issue is still open.
Is there any reason while is this still Private when google has two different copy of that pdf
indexed?
And the issue seems the be a more specialized version of https://bugs.php.net/bug.php?id=48597 which is
public.
------------------------------------------------------------------------
[2011-03-21 10:21:28] pajoye@php.net
Well, it was not supposed to be (confusing category). Anyway, fix will come as
usual, waiting for rthe CVE, etc.
------------------------------------------------------------------------
[2011-03-21 05:10:52] geissert@php.net
Needless to say, this issue should be treated as public. The bug title is more
than enough to find the pdf, and playing with a google search it is also possible
to make it reveal its cached page.
------------------------------------------------------------------------
[2011-03-20 22:40:45] pajoye@php.net
Description:
------------
https://students.mimuw.edu.pl/~ai292615/php_multipleupload_overwrite.pdf
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=54326&edit=1