Re: PHP 4.0 Bug #6496 Updated: The file upload feature opens a possible security hole
| From: | Stanislav Malyshev | Date: | Mon, 04 Sep 2000 10:46:47 +0000 |
| Subject: | Re: PHP 4.0 Bug #6496 Updated: The file upload feature opens a possible security hole | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-31917@lists.php.net to get a copy of this message | ||
BD>> A fix is in CVS which addresses this. And, no, the faked file
BD>> would not get deleted.
Another thought about the same fix. Why should we _care_ about any
variable except the temp file name is overwritten? The script will get
wrong data, that's true - but that won't be a "dangarous" wrong data,
since no precoditions and no special semantical menaning is given to
them. Only data that is important is the filename, since is has special
semantical meaning, that's what we should check. The rest user will check
by himself.
Any comments?
--
Stanislav Malyshev stas@zend.com http://www.zend.com/
+972-3-6139665 ext.106