PHP 4.0 Bug #6496: The file upload feature opens a possible security hole
| From: | luci at conexim dot com dot au | Date: | Sat, 02 Sep 2000 00:38:08 +0000 |
| Subject: | PHP 4.0 Bug #6496: The file upload feature opens a possible security hole | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-31629@lists.php.net to get a copy of this message | ||
From: luci@conexim.com.au
Operating system: Linux
PHP version: 4.0.2
PHP Bug Type: Other
Bug description: The file upload feature opens a possible security hole
Public internet users can potentially read files residing on the webserver through existing php code
using the file upload feature.
If there is a <FORM> with a "FILE" input field called "uploadedfile" for
example, followed by another form field with the same name "uploadedfile" which has the
value of the path of a file on the webserver ("/etc/passwd") works fine in many cases,
then the code handling the uploaded file will process the file pointed by the path given by the
second form element, not the file actually uploaded. If the code is meant to display the uploaded
file, or save it under a public URL, then the public users can see its contents.
There is a permission issue, as far as the ownership of the webserver process. But most setups use
nobody, or another use/group which can read certain files on the webserver.
I have not tested to see if the file gets deleted at the termination of the script as the temporary
files do.