Re: Re: [Fwd: (SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]
| From: | Lars Torben Wilson | Date: | Tue, 05 Sep 2000 01:41:47 +0000 |
| Subject: | Re: Re: [Fwd: (SRADV00001)Arbitraryfiledisclosurethrough PHP file upload] | ||
| References: | 1 2 3 4 5 | Groups: | php.dev php.general |
| Request: | Send a blank email to php-dev+get-32043@lists.php.net to get a copy of this message | ||
Ron Chmara writes:
> Oh, thats an easy one. :-)
> <?
> $validtmpdir = get_cfg_var("upload_tmp_dir");
> // get the path
>
> $uploaded_path_array = spilt("/","$userfile");
> //split the upload name into its components
>
> $inverted_path = array_reverse ($uploaded_path_array);
> // reverse the array, so any ending pathname will now be first
>
> $accurate_pathname = "$validtmpdir" . "$inverted_path[0]";
>
> if (file_exists($accurate_pathname )){
> //still look for proper temp name
> copy ("$accurate_pathname", "/place/to/put/uploaded/file");
> } else {
> echo "Not an uploaded file!";
> exit;
> }
> ?>
I think you can reduce the first few operations to one line to skip
the array processing (untested):
<?php
$safepath = get_cfg_var('upload_tmp_dir') . '/' . basename($userfile);
/* etc...*/
?>
Note: I haven't actually tried this, but it should be close...:)
--
+----------------------------------------------------------------+
|Torben Wilson <torben@php.net> Netmill iTech|
|http://www.coastnet.com/~torben http://www.netmill.fi|
|Ph: 1 250 383-9735 torben@netmill.fi|
+----------------------------------------------------------------+