Req #79286 [Opn->Csd]: Update basename comment for $_FILES["file"]["name"]
| From: | craig at craigfrancis dot co dot uk | Date: | Wed, 19 Feb 2020 16:48:42 +0000 |
| Subject: | Req #79286 [Opn->Csd]: Update basename comment for $_FILES["file"]["name"] | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-225627@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79286&edit=1
ID: 79286
User updated by: craig at craigfrancis dot co dot uk
Reported by: craig at craigfrancis dot co dot uk
Summary: Update basename comment for $_FILES["file"]["name"]
-Status: Open
+Status: Closed
Type: Feature/Change Request
Package: *General Issues
Operating System: N/A
PHP Version: master-Git-2020-02-19 (Git)
Block user comment: N
Private report: N
New Comment:
Has just been fixed:
https://github.com/php/php-src/commit/fb57ae9084a98ac5f06cd7b2d10205489b537e20
Previous Comments:
------------------------------------------------------------------------
[2020-02-19 15:45:13] craig at craigfrancis dot co dot uk
Description:
------------
In the PHP source code, the user supplied filename passes though _basename().
https://github.com/php/php-src/blob/0b4778c377a5753a0deb9cfc697d4f62acf93a29/main/rfc1867.c#L1139
The comment mentions this is due to Internet Explorer providing the "full path of the file on
the user's filesystem".
While that might be valid, it's much more important that the comment focuses on the security
issue this avoids.
For example, you will find examples of PHP code that does something like this:
$dest = __DIR__ . '/../../uploads/' . $_FILES["image"]['name']);
move_uploaded_file($_FILES['image']['tmp_name'], $dest);
Which would cause a problem if an "Evil Hacker" was to set the filename to a relative
path, e.g.
curl -F 'file=@example.php;filename=../../../example.php' https://example.com/upload/
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79286&edit=1