PHP 4.0 Bug #6496 Updated: The file upload feature opens a possible security hole
| From: | Bug Database | Date: | Mon, 04 Sep 2000 06:54:53 +0000 |
| Subject: | PHP 4.0 Bug #6496 Updated: The file upload feature opens a possible security hole | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-31896@lists.php.net to get a copy of this message | ||
ID: 6496
Updated by: rasmus
Reported By: luci@conexim.com.au
Status: Closed
Bug Type: Other
Assigned To:
Comments:
A fix is in CVS which addresses this. And, no, the faked file would not get deleted.
There is a second issue here related to scripts expecting a file upload being fed a form without a
file upload field at all. This is more of a documentation and user education issue though. We will
get some better code examples and data validation routines put up shortly. The general advice is
the same as always. Never trust user-supplied data and check any such data before using it.
Previous Comments:
[2000-09-01 20:38:08] luci@conexim.com.au
Public internet users can potentially read files residing on the webserver through existing php code
using the file upload feature.
If there is a <FORM> with a "FILE" input field called "uploadedfile" for
example, followed by another form field with the same name "uploadedfile" which has the
value of the path of a file on the webserver ("/etc/passwd") works fine in many cases,
then the code handling the uploaded file will process the file pointed by the path given by the
second form element, not the file actually uploaded. If the code is meant to display the uploaded
file, or save it under a public URL, then the public users can see its contents.
There is a permission issue, as far as the ownership of the webserver process. But most setups use
nobody, or another use/group which can read certain files on the webserver.
I have not tested to see if the file gets deleted at the termination of the script as the temporary
files do.
---------------------------------------------------------------------------
Full Bug description available at: http://bugs.php.net/?id=6496