Re: Re: [Fwd: (SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]

From: Date: Tue, 05 Sep 2000 01:35:10 +0000
Subject: Re: Re: [Fwd: (SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]
References: 1 2 3 4  Groups: php.dev php.general 
Request: Send a blank email to php-dev+get-32042@lists.php.net to get a copy of this message
Simon Edwards wrote: > Ron Chmara wrote: > > <? > > $validtmpdir = get_cfg_var("upload_tmp_dir"); > > /* make sure you're using an uploaded file */ > > if (strstr ("$validtmpdir", "$userfile") != 0){ > > copy ("$userfile" "/place/to/put/uploaded/file"); > > ..... > > } else { > > echo "Not an uploaded file!"; > > exit; > > } > > ?> > No, because if $validtmpdir = "/usr/tmp/" and > $userfile="/usr/tmp/../../etc/passwd" your code will accept it. The only > solution is to take the file part of $userfile and append it to > $validtmpdir before attempting a copy. This should ensure that you are > in the right directory. Oh, thats an easy one. :-) <? $validtmpdir = get_cfg_var("upload_tmp_dir"); // get the path $uploaded_path_array = spilt("/","$userfile"); //split the upload name into its components $inverted_path = array_reverse ($uploaded_path_array); // reverse the array, so any ending pathname will now be first $accurate_pathname = "$validtmpdir" . "$inverted_path[0]"; if (file_exists($accurate_pathname )){ //still look for proper temp name copy ("$accurate_pathname", "/place/to/put/uploaded/file"); } else { echo "Not an uploaded file!"; exit; } ?> -- Brought to you from iBop the iMac, a MacOS, Win95, Win98, LinuxPPC machine, which is currently in MacOS land. Your bopping may vary.

« previous php.dev (#32042) next »