#49919 [Opn->Bgs]: Wrong sample in doc
| From: | vrana@php.net | Date: | Fri, 13 Nov 2009 20:13:22 +0000 |
| Subject: | #49919 [Opn->Bgs]: Wrong sample in doc | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-3123@lists.php.net to get a copy of this message | ||
ID: 49919
Updated by: vrana@php.net
Reported By: getmequick at gmail dot com
-Status: Open
+Status: Bogus
Bug Type: Documentation problem
Operating System: Linux
PHP Version: 5.2.11
New Comment:
$_FILES['userfile']['name'] can contain full file path under some
circumstances.
Previous Comments:
------------------------------------------------------------------------
[2009-10-19 13:08:26] getmequick at gmail dot com
I suppose that PHP itself should take care about that
or if some version of PHP do not do that, it should be mentioned there.
------------------------------------------------------------------------
[2009-10-19 12:57:51] rquadling@php.net
What would happen if a cURL file upload session supplied a filename
with
directories (relative or absolute)?
------------------------------------------------------------------------
[2009-10-19 08:37:28] getmequick at gmail dot com
Description:
------------
Please take a look php code snippet shown here -
http://ru2.php.net/manual/en/features.file-upload.post-method.php
<?php
// In PHP versions earlier than 4.1.0, $HTTP_POST_FILES should be used
instead
// of $_FILES.
$uploaddir = '/var/www/uploads/';
$uploadfile = $uploaddir . basename($_FILES['userfile']['name']);
echo '<pre>';
if (move_uploaded_file($_FILES['userfile']['tmp_name'], $uploadfile))
{
echo "File is valid, and was successfully uploaded.\n";
} else {
echo "Possible file upload attack!\n";
}
echo 'Here is some more debugging info:';
print_r($_FILES);
print "</pre>";
?>
It seem to me useless apply basename( ) function as a
$_FILES['userfile']['name'] already return a filename only w/o
filepath.
Reproduce code:
---------------
<?php
// In PHP versions earlier than 4.1.0, $HTTP_POST_FILES should be used
instead
// of $_FILES.
$uploaddir = '/var/www/uploads/';
$uploadfile = $uploaddir . basename($_FILES['userfile']['name']);
echo '<pre>';
if (move_uploaded_file($_FILES['userfile']['tmp_name'], $uploadfile))
{
echo "File is valid, and was successfully uploaded.\n";
} else {
echo "Possible file upload attack!\n";
}
echo 'Here is some more debugging info:';
print_r($_FILES);
print "</pre>";
?>
Expected result:
----------------
<?php
// In PHP versions earlier than 4.1.0, $HTTP_POST_FILES should be used
instead
// of $_FILES.
$uploaddir = '/var/www/uploads/';
$uploadfile = $uploaddir . $_FILES['userfile']['name'];
echo '<pre>';
if (move_uploaded_file($_FILES['userfile']['tmp_name'], $uploadfile))
{
echo "File is valid, and was successfully uploaded.\n";
} else {
echo "Possible file upload attack!\n";
}
echo 'Here is some more debugging info:';
print_r($_FILES);
print "</pre>";
?>
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=49919&edit=1