Bug #1687 Updated: HTTP Upload with IE3
| From: | Bug Database | Date: | Sat, 10 Jul 1999 18:06:02 +0000 |
| Subject: | Bug #1687 Updated: HTTP Upload with IE3 | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-8277@lists.php.net to get a copy of this message | ||
ID: 1687
Updated by: markonen
Reported By: php@tainted.org
Status: Open
Bug Type: Other
Assigned To:
Comments:
My suggestion on this: change the file upload
functionality on the next major release (4.0?)
to fill the $userfile variable with the uploaded
filename relative to the php temp directory.
With our file upload implementation identical
otherwise, this would mean that a proper file
upload would never lead to $userfile value
that contains a slash or a backslash.
My opinion is that the security implications of
this problem seem to warrant breaking of backward
compatibility. My proposed change would:
a) force the script implementors to rework their
code, taking into consideration the security
implications of this problem
b) allow script implementors to check for a safe
$userfile to fopen() by just looking for slashes
or backslashes in it
Full Bug description available at: http://bugs.php.net/?id=1687