Re: Re: [Fwd: (SRADV00001) Arbitrary filedisclosurethrough PHP file upload]

From: Date: Tue, 05 Sep 2000 00:44:56 +0000
Subject: Re: Re: [Fwd: (SRADV00001) Arbitrary filedisclosurethrough PHP file upload]
References: 1 2  Groups: php.dev php.general 
Request: Send a blank email to php-dev+get-32022@lists.php.net to get a copy of this message
Ron Chmara wrote: > I am > talking about a security model where it is assumed that the server > files themselves may be uploaded. Sorry to be replying to myself, but: Would this work for most users, without having to patch, to make sure they are operating on a user uploaded file? <? $validtmpdir = get_cfg_var("upload_tmp_dir"); /* make sure you're using an uploaded file */ if (strstr ("$validtmpdir", "$userfile") != 0){ copy ("$userfile" "/place/to/put/uploaded/file"); ..... } else { echo "Not an uploaded file!"; exit; } ?> -Bop -- Brought to you from iBop the iMac, a MacOS, Win95, Win98, LinuxPPC machine, which is currently in MacOS land. Your bopping may vary.

« previous php.dev (#32022) next »