Re: FW: (SRADV00001) Arbitrary file disclosure through PHP file upload

From: Date: Mon, 04 Sep 2000 05:33:50 +0000
Subject: Re: FW: (SRADV00001) Arbitrary file disclosure through PHP file upload
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-31889@lists.php.net to get a copy of this message
> This just hit bugtraq. I'm formulating a reply presently, and will > cc you in on it. I think the author may be getting ahead of himself. > I still need to backpedal through the bug lists and see if this hasn't > been logged before.. He is a little bit confused. This has nothing to do with register_globals and turning off register_globals does nothing to fix this issue. I committed a patch which fixes the problem, but we will probably refine it. My suggestion is for people to simply check their $userfile_name variable and make sure they are copying a file from their tmp directory and nowhere else. And of course, your web server user id should not have access to sensitive files on your system anyway. -Rasmus

« previous php.dev (#31889) next »