PHP 4.0 Bug #7597: similar to #5375. when filtering double slashes from file upload
| From: | shensche at defcom dot de | Date: | Thu, 02 Nov 2000 18:49:10 +0000 |
| Subject: | PHP 4.0 Bug #7597: similar to #5375. when filtering double slashes from file upload | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-36810@lists.php.net to get a copy of this message | ||
From: shensche@defcom.de
Operating system: Linux 2.2.14
PHP version: 4.0.3pl1
PHP Bug Type: *Directory/Filesystem functions
Bug description: similar to #5375. when filtering double slashes from file upload
when filtering the double slashes from "tmp_name" from an $HTTP_POST_FILE, it cannot be
moved to the proper location anymore. this is similar to the problem addressed by bugreport #5375
with windowsNT.
config: php version 4.03pl1 in safe-mode
with mysql and gd
on a suse linux 6.4
well, but i know it is not so much of a problem: just do not tamper with the "tmp_name"
and everything is alright. does anyone know a reason for really doing that?
cheers,
sebastian
------------ example code -------------------------
<?php
if ($HTTP_POST_VARS["update"] == 1) {
$src = $HTTP_POST_FILES["upload_file"]["tmp_name"];
/*
* BUG here: double slashes are stripped and php cannot * move the uploaded file anymore.
*/
$src = ereg_replace ("//", "/", $src);
move_uploaded_file ($src, "pic.jpg");
}
?>
<html>
<body>
<form action="<?php echo $PHP_SELF ?>" method="POST"
enctype="multipart/form-data">
<input type="hidden" name="update" value="1">
hochladen: <input type="file" name="upload_file"><br>
<img src="pic.jpg"><br>
<input type="submit">
</form>
</body>
</html>
--
Edit Bug report at: http://bugs.php.net/?id=7597&edit=1