Re: FW: (SRADV00001) Arbitrary file disclosure through PHP file upload
| From: | Rasmus Lerdorf | Date: | Mon, 04 Sep 2000 05:33:50 +0000 |
| Subject: | Re: FW: (SRADV00001) Arbitrary file disclosure through PHP file upload | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-31889@lists.php.net to get a copy of this message | ||
> This just hit bugtraq. I'm formulating a reply presently, and will
> cc you in on it. I think the author may be getting ahead of himself.
> I still need to backpedal through the bug lists and see if this hasn't
> been logged before..
He is a little bit confused. This has nothing to do with register_globals
and turning off register_globals does nothing to fix this issue. I
committed a patch which fixes the problem, but we will probably refine it.
My suggestion is for people to simply check their $userfile_name variable
and make sure they are copying a file from their tmp directory and nowhere
else. And of course, your web server user id should not have access to
sensitive files on your system anyway.
-Rasmus