Req #79286 [Opn->Csd]: Update basename comment for $_FILES["file"]["name"]

From: Date: Wed, 19 Feb 2020 16:48:42 +0000
Subject: Req #79286 [Opn->Csd]: Update basename comment for $_FILES["file"]["name"]
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225627@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79286&edit=1 ID: 79286 User updated by: craig at craigfrancis dot co dot uk Reported by: craig at craigfrancis dot co dot uk Summary: Update basename comment for $_FILES["file"]["name"] -Status: Open +Status: Closed Type: Feature/Change Request Package: *General Issues Operating System: N/A PHP Version: master-Git-2020-02-19 (Git) Block user comment: N Private report: N New Comment: Has just been fixed: https://github.com/php/php-src/commit/fb57ae9084a98ac5f06cd7b2d10205489b537e20 Previous Comments: ------------------------------------------------------------------------ [2020-02-19 15:45:13] craig at craigfrancis dot co dot uk Description: ------------ In the PHP source code, the user supplied filename passes though _basename(). https://github.com/php/php-src/blob/0b4778c377a5753a0deb9cfc697d4f62acf93a29/main/rfc1867.c#L1139 The comment mentions this is due to Internet Explorer providing the "full path of the file on the user's filesystem". While that might be valid, it's much more important that the comment focuses on the security issue this avoids. For example, you will find examples of PHP code that does something like this: $dest = __DIR__ . '/../../uploads/' . $_FILES["image"]['name']); move_uploaded_file($_FILES['image']['tmp_name'], $dest); Which would cause a problem if an "Evil Hacker" was to set the filename to a relative path, e.g. curl -F 'file=@example.php;filename=../../../example.php' https://example.com/upload/ ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79286&edit=1

« previous php.bugs (#225627) next »