Re: PHP 4.0 Bug #6496 Updated: The file upload feature opens a possible security hole

From: Date: Mon, 04 Sep 2000 17:27:49 +0000
Subject: Re: PHP 4.0 Bug #6496 Updated: The file upload feature opens a possible security hole
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-31951@lists.php.net to get a copy of this message
> RL>> I think the others are important as well. People may very well rely on > RL>> the file size and file type to make decisions on where to place the file > RL>> or whether to even accept it or not. If people can spoof those other > RL>> variables they may be able to trick a receiving script into doing nasty > RL>> things. > > You can "spoof" those variables even without any nasty tricks - those (as > opposed to $file variable) are copied exactly as passed by the user agent, > so they are under complete user control anyway. $file is made by PHP. ?? $file_type and $file_size are created by PHP as well. -Rasmus

« previous php.dev (#31951) next »