Re: File Upload Security fix

From: Date: Mon, 04 Sep 2000 15:06:51 +0000
Subject: Re: File Upload Security fix
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-31936@lists.php.net to get a copy of this message
> That's a bad fix. If a have form upload variable named "myfile", why I > can't have checkbox named "myfile_was_uploaded"? And what it's going to > do, just swallow that variable silently and make me pull my hair out > trying to figure where did that checkbox go? I didn't say it was a great fix. It was a quick-fix written to stop the explicit exploit, which it does. The real fix is to have $userfile_tmpfile be just the temporary filename and then either add a helper function or teach people to use cfg_get_var() to fetch the file upload tmp dir and append the temp filename to it when they do their copy. -Rasmus

« previous php.dev (#31936) next »