Bug #1687: HTTP Upload with IE3
| From: | php at tainted dot org | Date: | Fri, 09 Jul 1999 14:51:13 +0000 |
| Subject: | Bug #1687: HTTP Upload with IE3 | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-8253@lists.php.net to get a copy of this message | ||
From: php@tainted.org
Operating system: Linux 2.0.x/glibc2.0
PHP version: 3.0.9
PHP Bug Type: Other
Bug description: HTTP Upload with IE3
HTTP Uploading is built into PHP3.
HTTP Uploading is not supported by IE3.
Having a form with an entry like:
<INPUT ENCTYPE="multipart/form-data" NAME="userfile"
TYPE="file">
Should make a browser provide a string gadget and a "Browse..." button to locally select a
file to upload.
PHP3 normally accepts the data stream and puts it into
a temporary file. When the form is submitted, the form
handler will have a variable of "$userfile" which contains
the name of the file PHP3 accepted it as, most
webmasters check to make sure that the $userfile is not "" or "none" and then
proceed to fopen($userfile,...) for their
needs.
IE3 does not support HTTP Upload, but decides to give
the browser user a string gadget nevertheless. The user
may enter the name of a file on the server "/etc/fstab" (or worse), which is sent to PHP3
from IE3 and the HTTP-Upload
portion of the form is not triggered.
This leaves the $userfile variable with the name of the
file the user has entered, which many scripts would just
fopen() and use.
I believe the only work around for this is to document
it and ensure to check the filename that it starts with
the php3 temporary path; other methods could likely be
exploited.