Req #79286 [NEW]: Update basename comment for $_FILES["file"]["name"]
| From: | craig at craigfrancis dot co dot uk | Date: | Wed, 19 Feb 2020 15:45:13 +0000 |
| Subject: | Req #79286 [NEW]: Update basename comment for $_FILES["file"]["name"] | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-225622@lists.php.net to get a copy of this message | ||
From: craig at craigfrancis dot co dot uk
Operating system: N/A
PHP version: master-Git-2020-02-19 (Git)
Package: *General Issues
Bug Type: Feature/Change Request
Bug description:Update basename comment for $_FILES["file"]["name"]
Description:
------------
In the PHP source code, the user supplied filename passes though
_basename().
https://github.com/php/php-src/blob/0b4778c377a5753a0deb9cfc697d4f62acf93a29/main/rfc1867.c#L1139
The comment mentions this is due to Internet Explorer providing the
"full path of the file on the user's filesystem".
While that might be valid, it's much more important that the comment
focuses on the security issue this avoids.
For example, you will find examples of PHP code that does something like
this:
$dest = __DIR__ . '/../../uploads/' . $_FILES["image"]['name']);
move_uploaded_file($_FILES['image']['tmp_name'], $dest);
Which would cause a problem if an "Evil Hacker" was to set the filename
to a relative path, e.g.
curl -F 'file=@example.php;filename=../../../example.php'
https://example.com/upload/
--
Edit bug report at https://bugs.php.net/bug.php?id=79286&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=79286&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=79286&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=79286&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=79286&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=79286&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=79286&r=support
Expected behavior: https://bugs.php.net/fix.php?id=79286&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=79286&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=79286&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=79286&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=79286&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=79286&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=79286&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=79286&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=79286&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=79286&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=79286&r=mysqlcfg