#49919 [Opn->Bgs]: Wrong sample in doc

From: Date: Fri, 13 Nov 2009 20:13:22 +0000
Subject: #49919 [Opn->Bgs]: Wrong sample in doc
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-3123@lists.php.net to get a copy of this message
ID: 49919 Updated by: vrana@php.net Reported By: getmequick at gmail dot com -Status: Open +Status: Bogus Bug Type: Documentation problem Operating System: Linux PHP Version: 5.2.11 New Comment: $_FILES['userfile']['name'] can contain full file path under some circumstances. Previous Comments: ------------------------------------------------------------------------ [2009-10-19 13:08:26] getmequick at gmail dot com I suppose that PHP itself should take care about that or if some version of PHP do not do that, it should be mentioned there. ------------------------------------------------------------------------ [2009-10-19 12:57:51] rquadling@php.net What would happen if a cURL file upload session supplied a filename with directories (relative or absolute)? ------------------------------------------------------------------------ [2009-10-19 08:37:28] getmequick at gmail dot com Description: ------------ Please take a look php code snippet shown here - http://ru2.php.net/manual/en/features.file-upload.post-method.php <?php // In PHP versions earlier than 4.1.0, $HTTP_POST_FILES should be used instead // of $_FILES. $uploaddir = '/var/www/uploads/'; $uploadfile = $uploaddir . basename($_FILES['userfile']['name']); echo '<pre>'; if (move_uploaded_file($_FILES['userfile']['tmp_name'], $uploadfile)) { echo "File is valid, and was successfully uploaded.\n"; } else { echo "Possible file upload attack!\n"; } echo 'Here is some more debugging info:'; print_r($_FILES); print "</pre>"; ?> It seem to me useless apply basename( ) function as a $_FILES['userfile']['name'] already return a filename only w/o filepath. Reproduce code: --------------- <?php // In PHP versions earlier than 4.1.0, $HTTP_POST_FILES should be used instead // of $_FILES. $uploaddir = '/var/www/uploads/'; $uploadfile = $uploaddir . basename($_FILES['userfile']['name']); echo '<pre>'; if (move_uploaded_file($_FILES['userfile']['tmp_name'], $uploadfile)) { echo "File is valid, and was successfully uploaded.\n"; } else { echo "Possible file upload attack!\n"; } echo 'Here is some more debugging info:'; print_r($_FILES); print "</pre>"; ?> Expected result: ---------------- <?php // In PHP versions earlier than 4.1.0, $HTTP_POST_FILES should be used instead // of $_FILES. $uploaddir = '/var/www/uploads/'; $uploadfile = $uploaddir . $_FILES['userfile']['name']; echo '<pre>'; if (move_uploaded_file($_FILES['userfile']['tmp_name'], $uploadfile)) { echo "File is valid, and was successfully uploaded.\n"; } else { echo "Possible file upload attack!\n"; } echo 'Here is some more debugging info:'; print_r($_FILES); print "</pre>"; ?> ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=49919&edit=1

« previous php.doc.bugs (#3123) next »