Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Thu, 07 Sep 2000 12:04:25 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2 3 4 5 6 7 8 9 10  Groups: php.dev 
Request: Send a blank email to php-dev+get-32531@lists.php.net to get a copy of this message
Thies Arntzen <thies@digicol.de> wrote: > -but- i'm pretty sure you (as a decent person) would agree > that no browser-generated request would ever contain %00 in > the URL, wouldn't you? (i've never seen a -NULL- key on a > keyboard, no widely used encoding has \0 bytes in a character > stream - for obvious reasons;) PHP-generated HTML may quite easily contain such things - e.g.: $foo = "abc\0def"; echo '<input type="hidden" name="foo" value="', htmlentities(urlencode($foo)),'">';

« previous php.dev (#32531) next »