Re: PHP File Upload Security Hole - Still No Fix?
| From: | Thies Arntzen | Date: | Thu, 07 Sep 2000 11:24:06 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32526@lists.php.net to get a copy of this message | ||
On Thu, Sep 07, 2000 at 10:42:01AM +0100, Jon Ribbens wrote:
> Zeev Suraski <zeev@zend.com> wrote:
> > In the particular place you pointed out, the lack of binary safety:
> > a. Probably has no implications at all.
>
> It looked to me like it meant that you can't pass binary data via CGI
> variables. If that's the case, then it *does* have implications,
> and *is* a bug *if and only if it is not documented*.
please "enligthen" me on how to pass binary data (namely data
that contains '\0') to a cgi.
- have you read (& understood) the related rfc?
- have you read (& understood) the source you're complaining about?
thanx,
tc