Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Wed, 06 Sep 2000 10:21:11 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32338@lists.php.net to get a copy of this message | ||
Ron Chmara <ron@opus1.com> wrote:
> > No, data from the user is untrusted. Data that PHP itself provides
> > (i.e. the filename of the local file) is (and has to be) trusted.
>
> This is poor coding practice,
You have almost entirely misunderstood everything I said in the post
you were replying to. I suggest you go back and read it again.