Re: File Upload Security fix

From: Date: Mon, 04 Sep 2000 17:02:45 +0000
Subject: Re: File Upload Security fix
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-31947@lists.php.net to get a copy of this message
RL>> The real fix is to have $userfile_tmpfile be just the temporary filename RL>> and then either add a helper function or teach people to use RL>> cfg_get_var() to fetch the file upload tmp dir and append the temp RL>> filename to it when they do their copy. Exactly. But what I was saying it won't hurt if you compare just exact name of the variable, not a "starting with", because we don't really care for other variables. -- Stanislav Malyshev stas@zend.com http://www.zend.com/ +972-3-6139665 ext.106

« previous php.dev (#31947) next »