Bug #1687: HTTP Upload with IE3

From: Date: Fri, 09 Jul 1999 14:51:13 +0000
Subject: Bug #1687: HTTP Upload with IE3
Groups: php.dev 
Request: Send a blank email to php-dev+get-8253@lists.php.net to get a copy of this message
From: php@tainted.org Operating system: Linux 2.0.x/glibc2.0 PHP version: 3.0.9 PHP Bug Type: Other Bug description: HTTP Upload with IE3 HTTP Uploading is built into PHP3. HTTP Uploading is not supported by IE3. Having a form with an entry like: <INPUT ENCTYPE="multipart/form-data" NAME="userfile" TYPE="file"> Should make a browser provide a string gadget and a "Browse..." button to locally select a file to upload. PHP3 normally accepts the data stream and puts it into a temporary file. When the form is submitted, the form handler will have a variable of "$userfile" which contains the name of the file PHP3 accepted it as, most webmasters check to make sure that the $userfile is not "" or "none" and then proceed to fopen($userfile,...) for their needs. IE3 does not support HTTP Upload, but decides to give the browser user a string gadget nevertheless. The user may enter the name of a file on the server "/etc/fstab" (or worse), which is sent to PHP3 from IE3 and the HTTP-Upload portion of the form is not triggered. This leaves the $userfile variable with the name of the file the user has entered, which many scripts would just fopen() and use. I believe the only work around for this is to document it and ensure to check the filename that it starts with the php3 temporary path; other methods could likely be exploited.

« previous php.dev (#8253) next »