Re: Re: [Fwd: (SRADV00001)Arbitraryfiledisclosurethrough PHP file upload]
| From: | Ron Chmara | Date: | Tue, 05 Sep 2000 01:35:10 +0000 |
| Subject: | Re: Re: [Fwd: (SRADV00001)Arbitraryfiledisclosurethrough PHP file upload] | ||
| References: | 1 2 3 4 | Groups: | php.dev php.general |
| Request: | Send a blank email to php-general+get-15199@lists.php.net to get a copy of this message | ||
Simon Edwards wrote:
> Ron Chmara wrote:
> > <?
> > $validtmpdir = get_cfg_var("upload_tmp_dir");
> > /* make sure you're using an uploaded file */
> > if (strstr ("$validtmpdir", "$userfile") != 0){
> > copy ("$userfile" "/place/to/put/uploaded/file");
> > .....
> > } else {
> > echo "Not an uploaded file!";
> > exit;
> > }
> > ?>
> No, because if $validtmpdir = "/usr/tmp/" and
> $userfile="/usr/tmp/../../etc/passwd" your code will accept it. The only
> solution is to take the file part of $userfile and append it to
> $validtmpdir before attempting a copy. This should ensure that you are
> in the right directory.
Oh, thats an easy one. :-)
<?
$validtmpdir = get_cfg_var("upload_tmp_dir");
// get the path
$uploaded_path_array = spilt("/","$userfile");
//split the upload name into its components
$inverted_path = array_reverse ($uploaded_path_array);
// reverse the array, so any ending pathname will now be first
$accurate_pathname = "$validtmpdir" . "$inverted_path[0]";
if (file_exists($accurate_pathname )){
//still look for proper temp name
copy ("$accurate_pathname", "/place/to/put/uploaded/file");
} else {
echo "Not an uploaded file!";
exit;
}
?>
--
Brought to you from iBop the iMac, a MacOS, Win95, Win98, LinuxPPC machine,
which is currently in MacOS land. Your bopping may vary.