PHP 4.0 Bug #6496 Updated: The file upload feature opens a possible security hole

From: Date: Mon, 04 Sep 2000 09:55:53 +0000
Subject: PHP 4.0 Bug #6496 Updated: The file upload feature opens a possible security hole
Groups: php.dev 
Request: Send a blank email to php-dev+get-31911@lists.php.net to get a copy of this message
ID: 6496 Updated by: stas Reported By: luci@conexim.com.au Status: Analyzed Bug Type: Other Assigned To: Comments: Since we don't have a fix for a "fake upload" yet, as I understand, and since recent patch breaks innocent variables happening to start with same prefix as some file upload, and since no docs still exist - I guess it would be a good thing to reponen this report until we have a full fix and docs. Previous Comments: [2000-09-04 02:54:53] rasmus@php.net A fix is in CVS which addresses this. And, no, the faked file would not get deleted. There is a second issue here related to scripts expecting a file upload being fed a form without a file upload field at all. This is more of a documentation and user education issue though. We will get some better code examples and data validation routines put up shortly. The general advice is the same as always. Never trust user-supplied data and check any such data before using it. --------------------------------------------------------------------------- [2000-09-01 20:38:08] luci@conexim.com.au Public internet users can potentially read files residing on the webserver through existing php code using the file upload feature. If there is a <FORM> with a "FILE" input field called "uploadedfile" for example, followed by another form field with the same name "uploadedfile" which has the value of the path of a file on the webserver ("/etc/passwd") works fine in many cases, then the code handling the uploaded file will process the file pointed by the path given by the second form element, not the file actually uploaded. If the code is meant to display the uploaded file, or save it under a public URL, then the public users can see its contents. There is a permission issue, as far as the ownership of the webserver process. But most setups use nobody, or another use/group which can read certain files on the webserver. I have not tested to see if the file gets deleted at the termination of the script as the temporary files do. --------------------------------------------------------------------------- Full Bug description available at: http://bugs.php.net/?id=6496

« previous php.dev (#31911) next »