Re: File Upload Security fix

From: Date: Mon, 04 Sep 2000 10:26:59 +0000
Subject: Re: File Upload Security fix
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-31913@lists.php.net to get a copy of this message
RL>> We probably need a way to mark a variable in the global symbol table as RL>> non-overwritable during GPC handling. Note that this has nothing to do RL>> with whether register_globals is on or off. This file upload security RL>> vulnerability is due to a POST var overwriting another POST var in RL>> whatever context it is in. That's not exactly right. When you are using not globals but HTTP_POST_FILES you get a structure that cannot be overwritten by plain variables. I guess that's what the reporter meant. -- Stanislav Malyshev stas@zend.com http://www.zend.com/ +972-3-6139665 ext.106

« previous php.dev (#31913) next »