Re: File Upload Security fix
| From: | Rasmus Lerdorf | Date: | Mon, 04 Sep 2000 15:06:51 +0000 |
| Subject: | Re: File Upload Security fix | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-31936@lists.php.net to get a copy of this message | ||
> That's a bad fix. If a have form upload variable named "myfile", why I
> can't have checkbox named "myfile_was_uploaded"? And what it's going to
> do, just swallow that variable silently and make me pull my hair out
> trying to figure where did that checkbox go?
I didn't say it was a great fix. It was a quick-fix written to stop the
explicit exploit, which it does.
The real fix is to have $userfile_tmpfile be just the temporary filename
and then either add a helper function or teach people to use
cfg_get_var() to fetch the file upload tmp dir and append the temp
filename to it when they do their copy.
-Rasmus