Re: File Upload Security fix
| From: | Stanislav Malyshev | Date: | Mon, 04 Sep 2000 17:02:45 +0000 |
| Subject: | Re: File Upload Security fix | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-31947@lists.php.net to get a copy of this message | ||
RL>> The real fix is to have $userfile_tmpfile be just the temporary filename
RL>> and then either add a helper function or teach people to use
RL>> cfg_get_var() to fetch the file upload tmp dir and append the temp
RL>> filename to it when they do their copy.
Exactly. But what I was saying it won't hurt if you compare just exact
name of the variable, not a "starting with", because we don't really care
for other variables.
--
Stanislav Malyshev stas@zend.com http://www.zend.com/
+972-3-6139665 ext.106