#49919 [NEW]: Wrong sample in doc
| From: | getmequick at gmail dot com | Date: | Mon, 19 Oct 2009 08:37:29 +0000 |
| Subject: | #49919 [NEW]: Wrong sample in doc | ||
| Groups: | php.doc.bugs | ||
| Request: | Send a blank email to doc-bugs+get-2966@lists.php.net to get a copy of this message | ||
From: getmequick at gmail dot com
Operating system: Linux
PHP version: 5.2.11
PHP Bug Type: Documentation problem
Bug description: Wrong sample in doc
Description:
------------
Please take a look php code snippet shown here -
http://ru2.php.net/manual/en/features.file-upload.post-method.php
<?php
// In PHP versions earlier than 4.1.0, $HTTP_POST_FILES should be used
instead
// of $_FILES.
$uploaddir = '/var/www/uploads/';
$uploadfile = $uploaddir . basename($_FILES['userfile']['name']);
echo '<pre>';
if (move_uploaded_file($_FILES['userfile']['tmp_name'], $uploadfile)) {
echo "File is valid, and was successfully uploaded.\n";
} else {
echo "Possible file upload attack!\n";
}
echo 'Here is some more debugging info:';
print_r($_FILES);
print "</pre>";
?>
It seem to me useless apply basename( ) function as a
$_FILES['userfile']['name'] already return a filename only w/o filepath.
Reproduce code:
---------------
<?php
// In PHP versions earlier than 4.1.0, $HTTP_POST_FILES should be used
instead
// of $_FILES.
$uploaddir = '/var/www/uploads/';
$uploadfile = $uploaddir . basename($_FILES['userfile']['name']);
echo '<pre>';
if (move_uploaded_file($_FILES['userfile']['tmp_name'], $uploadfile)) {
echo "File is valid, and was successfully uploaded.\n";
} else {
echo "Possible file upload attack!\n";
}
echo 'Here is some more debugging info:';
print_r($_FILES);
print "</pre>";
?>
Expected result:
----------------
<?php
// In PHP versions earlier than 4.1.0, $HTTP_POST_FILES should be used
instead
// of $_FILES.
$uploaddir = '/var/www/uploads/';
$uploadfile = $uploaddir . $_FILES['userfile']['name'];
echo '<pre>';
if (move_uploaded_file($_FILES['userfile']['tmp_name'], $uploadfile)) {
echo "File is valid, and was successfully uploaded.\n";
} else {
echo "Possible file upload attack!\n";
}
echo 'Here is some more debugging info:';
print_r($_FILES);
print "</pre>";
?>
--
Edit bug report at http://bugs.php.net/?id=49919&edit=1
--
Try a snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=49919&r=trysnapshot52
Try a snapshot (PHP 5.3): http://bugs.php.net/fix.php?id=49919&r=trysnapshot53
Try a snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=49919&r=trysnapshot60
Fixed in SVN: http://bugs.php.net/fix.php?id=49919&r=fixed
Fixed in SVN and need be documented: http://bugs.php.net/fix.php?id=49919&r=needdocs
Fixed in release: http://bugs.php.net/fix.php?id=49919&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=49919&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=49919&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=49919&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=49919&r=support
Expected behavior: http://bugs.php.net/fix.php?id=49919&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=49919&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=49919&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=49919&r=globals
PHP 4 support discontinued: http://bugs.php.net/fix.php?id=49919&r=php4
Daylight Savings: http://bugs.php.net/fix.php?id=49919&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=49919&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=49919&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=49919&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=49919&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=49919&r=mysqlcfg