File Upload Security fix

From: Date: Mon, 04 Sep 2000 05:30:08 +0000
Subject: File Upload Security fix
Groups: php.dev 
Request: Send a blank email to php-dev+get-31888@lists.php.net to get a copy of this message
We probably need a way to mark a variable in the global symbol table as non-overwritable during GPC handling. Note that this has nothing to do with whether register_globals is on or off. This file upload security vulnerability is due to a POST var overwriting another POST var in whatever context it is in. I hacked in a fix right now that makes sure that if your file upload field name is 'abc' then you can't set any variables in the same form that begin with 'apc'. -Rasmus

« previous php.dev (#31888) next »