Re: Re: [Fwd:(SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]

From: Date: Tue, 05 Sep 2000 02:36:21 +0000
Subject: Re: Re: [Fwd:(SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]
References: 1 2 3 4 5 6  Groups: php.dev php.general 
Request: Send a blank email to php-dev+get-32058@lists.php.net to get a copy of this message
Lars Torben Wilson wrote: > > Ron Chmara writes: > > Oh, thats an easy one. :-) > > <? > > $validtmpdir = get_cfg_var("upload_tmp_dir"); > > // get the path > > > > $uploaded_path_array = spilt("/","$userfile"); > > //split the upload name into its components > > > > $inverted_path = array_reverse ($uploaded_path_array); > > // reverse the array, so any ending pathname will now be first > > > > $accurate_pathname = "$validtmpdir" . "$inverted_path[0]"; > > > > if (file_exists($accurate_pathname )){ > > //still look for proper temp name > > copy ("$accurate_pathname", "/place/to/put/uploaded/file"); > > } else { > > echo "Not an uploaded file!"; > > exit; > > } > > ?> > > I think you can reduce the first few operations to one line to skip > the array processing (untested): > > <?php > $safepath = get_cfg_var('upload_tmp_dir') . '/' . basename($userfile); Hi, You can also add a little (untested) embellishment such as: if ($userfile != basename($userfile)) { mail($WEBMASTER, "UserFile Attack Detected", "IP Address = '$REMOTE_ADDR'\nUser id = ...."); echo "Foiled again<BR>"; } else { process the data } Ciao, Andreas

« previous php.dev (#32058) next »