#31398 [Opn]: File Upload Original name problem with magic_quotes_gpc = On

From: Date: Thu, 13 Jan 2005 19:10:59 +0000
Subject: #31398 [Opn]: File Upload Original name problem with magic_quotes_gpc = On
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-72081@lists.php.net to get a copy of this message
 ID:               31398
 Updated by:       theseer@php.net
-Summary:          File Upload Original name problem
 Reported By:      lobo235 at gmail dot com
 Status:           Open
-Bug Type:         Documentation problem
+Bug Type:         Scripting Engine problem
 Operating System: Windows and Linux
 PHP Version:      4CVS-2005-01-04 (stable)
 New Comment:

I don't consider that a documentation problem but rather an engine bug
(?)


Previous Comments:
------------------------------------------------------------------------

[2005-01-11 13:03:40] fsolinas at it dot tiscali dot com

I've been able to reproduce this bug on PHP 4.3.10 with
magic_quotes_gpc = On.
It's *not* reproducible turning off magic_quotes_gpc,
because the array element containing the (original) file
name is preserved "intact" this way.

This bug seems to have been introduced in 4.3.10, and breaks
many document management systems that rely on
$_FILES['userfile']['name'] as the name of the file
uploaded, definitely forcing users to *not* use single
quotes in filename.

Do you plan to write a patch to fix this behaviour?

------------------------------------------------------------------------

[2005-01-05 16:18:51] lobo235 at gmail dot com

It may be only PHP4 specific, I do remember it working at one point
though using PHP4 a couple of months ago. I had written a file upload
script for one of my sites and I remember testing to see what types of
filenames it would support and the apostrophes worked fine then. It
wasn't until just recently that my host upgraded to 4.3.10 that I
started to notice the problem, now my script does not work as it used
to.

------------------------------------------------------------------------

[2005-01-05 10:11:50] vrana@php.net

I can't reproduce this on PHP 5.0.2 with php.ini-dist, Apache 2 and
Windows. "lobo235's fam.jpg" becomes "lobo235\'s fam.jpg" or
"lobo235's
fam.jpg" with magic_quotes_gpc=Off.

Maybe it's PHP 4 specific.

------------------------------------------------------------------------

[2005-01-05 09:03:22] derick@php.net

Yeah, I agree... the documentation should mention this issue.

------------------------------------------------------------------------

[2005-01-04 22:49:51] lobo235 at gmail dot com

If I remember correctly, PHP used to handle filenames of this type just
fine. I know that other scripting languages are able to handle these
types of filenames just fine. Is there any way that this can be
implemented in a future version? It seems like if an array element is
going to be set to the "original" file name it should work all the time
or not at all. It is misleading when one reads the documentation
concerning Handling file uploads. It says:

$_FILES['userfile']['name']

    The original name of the file on the client machine. 

To me this says that no matter what they've named their file this array
element always gets set to the name of the file on the client machine.
Maybe a change is needed in the documentation.

------------------------------------------------------------------------

The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
    http://bugs.php.net/31398

-- 
Edit this bug report at http://bugs.php.net/?id=31398&edit=1


Thread (8 messages)

« previous php.bugs (#72081) next »