RE: [PHP-DEV] FW: (SRADV00001) Arbitrary file disclosure throughPHP file upload

From: Date: Mon, 04 Sep 2000 06:42:43 +0000
Subject: RE: [PHP-DEV] FW: (SRADV00001) Arbitrary file disclosure throughPHP file upload
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-31894@lists.php.net to get a copy of this message
> He is a little bit confused. This has nothing to do with register_globals > and turning off register_globals does nothing to fix this issue. I > committed a patch which fixes the problem, but we will probably refine it. More than a little! I posted some more information to bugtraq so that people can view the bug in the database. You might want to just tag a note on that bug id saying a patch has been committed and will be available shortly... aleph usually takes about 4-8 hours to get to messages.. > My suggestion is for people to simply check their $userfile_name variable > and make sure they are copying a file from their tmp directory and nowhere > else. And of course, your web server user id should not have access to > sensitive files on your system anyway. Well, I made the suggestion to check the filesize.. although your suggestion should have been obvious to me. Ngggh... that's what I get for trying to think at 2 in the morning. :\ ~ Signal 11

« previous php.dev (#31894) next »