Re: Re: [Fwd: (SRADV00001) Arbitraryfiledisclosurethrough PHP file upload]

From: Date: Tue, 05 Sep 2000 00:59:44 +0000
Subject: Re: Re: [Fwd: (SRADV00001) Arbitraryfiledisclosurethrough PHP file upload]
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-15192@lists.php.net to get a copy of this message
Ron Chmara wrote: > Would this work for most users, without having to patch, to make sure > they are operating on a user uploaded file? > <? > $validtmpdir = get_cfg_var("upload_tmp_dir"); > /* make sure you're using an uploaded file */ > if (strstr ("$validtmpdir", "$userfile") != 0){ > copy ("$userfile" "/place/to/put/uploaded/file"); > ..... > } else { > echo "Not an uploaded file!"; > exit; > } > ?> No, because if $validtmpdir = "/usr/tmp/" and $userfile="/usr/tmp/../../etc/passwd" your code will accept it. The only solution is to take the file part of $userfile and append it to $validtmpdir before attempting a copy. This should ensure that you are in the right directory. -- Simon Edwards Animated Design, Melbourne http://www.animated.net.au/ Ph: (03) 98850990

« previous php.general (#15192) next »