#31503 [NEW]: $_FILES array returns incorrect values
| From: | mail1 at prettyworthless dot com | Date: | Wed, 12 Jan 2005 02:00:30 +0000 |
| Subject: | #31503 [NEW]: $_FILES array returns incorrect values | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-71903@lists.php.net to get a copy of this message | ||
From: mail1 at prettyworthless dot com
Operating system: FreeBSD
PHP version: 4.3.10
PHP Bug Type: Unknown/Other Function
Bug description: $_FILES array returns incorrect values
Description:
------------
If I create an input type=files in the html form
Then in the target php script use the $_FILES array to get the info
All works well - uploads work fine.
But . . . if the file name contains a single quote mark, the name from
$_FILES is not correct. The resulting $_FILES['file']['name'] gives the
name from the next character after the single quote to the end (like a
reverse truncation). Only the single quote casues this (that I have
found). The upload still works, but with a wierd file name result.
Went back and tested with 4.3.4 and it works correctly.
Reproduce code:
---------------
html upload page (test.htm):
<form action="test.php" method="post"
enctype="multipart/form-data">
File: <input type=file name="file" size=30><br>
<input type=submit name="submit" value="Upload File"></form>
php processing page (test.php):
<?php
print_r($_FILES);
?>
Then try and use any file name with a single quote in it.
Expected result:
----------------
$_FILES['file']['name'] should have the file name - such as abcd'efg.txt
Actual result:
--------------
$_FILES['file']['name'] will have the cut-off name - such as efg.txt
--
Edit bug report at http://bugs.php.net/?id=31503&edit=1
--
Try a CVS snapshot (php4): http://bugs.php.net/fix.php?id=31503&r=trysnapshot4
Try a CVS snapshot (php5.0): http://bugs.php.net/fix.php?id=31503&r=trysnapshot50
Try a CVS snapshot (php5.1): http://bugs.php.net/fix.php?id=31503&r=trysnapshot51
Fixed in CVS: http://bugs.php.net/fix.php?id=31503&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=31503&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=31503&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=31503&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=31503&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=31503&r=support
Expected behavior: http://bugs.php.net/fix.php?id=31503&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=31503&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=31503&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=31503&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=31503&r=php3
Daylight Savings: http://bugs.php.net/fix.php?id=31503&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=31503&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=31503&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=31503&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=31503&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=31503&r=mysqlcfg