Re: PHP 4.0 Bug #6496 Updated: The file upload feature opens a possible security hole
| From: | Rasmus Lerdorf | Date: | Mon, 04 Sep 2000 16:06:00 +0000 |
| Subject: | Re: PHP 4.0 Bug #6496 Updated: The file upload feature opens a possible security hole | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-31943@lists.php.net to get a copy of this message | ||
> BD>> A fix is in CVS which addresses this. And, no, the faked file
> BD>> would not get deleted.
>
> Another thought about the same fix. Why should we _care_ about any
> variable except the temp file name is overwritten? The script will get
> wrong data, that's true - but that won't be a "dangarous" wrong data,
> since no precoditions and no special semantical menaning is given to
> them. Only data that is important is the filename, since is has special
> semantical meaning, that's what we should check. The rest user will check
> by himself.
>
> Any comments?
I think the others are important as well. People may very well rely on
the file size and file type to make decisions on where to place the file
or whether to even accept it or not. If people can spoof those other
variables they may be able to trick a receiving script into doing nasty
things.
-Rasmus