Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Tue, 05 Sep 2000 12:50:30 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32139@lists.php.net to get a copy of this message | ||
Stanislav Malyshev <stas@zend.com> wrote:
> I guess we just should say in large friendly letters in the manual "use
> HTTP_POST_FILES when you upload files, doing otherwise is insecure!".
Yes, this is exactly right!
> At least until we make it safe.
I don't see how you can ever do this.