Re: Re: [Fwd: (SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]

From: Date: Tue, 05 Sep 2000 06:37:29 +0000
Subject: Re: Re: [Fwd: (SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]
References: 1  Groups: php.dev php.general 
Request: Send a blank email to php-dev+get-32089@lists.php.net to get a copy of this message
LTW>> <?php LTW>> $safepath = get_cfg_var('upload_tmp_dir') . '/' . LTW>> basename($userfile); LTW>> LTW>> /* etc...*/ LTW>> ?> That's closer to the point. Now why won't PHP really do it? -- Stanislav Malyshev stas@zend.com http://www.zend.com/ +972-3-6139665 ext.106

« previous php.dev (#32089) next »