Re: is_uploaded_file() security

From: Date: Wed, 22 Oct 2003 15:46:32 +0000
Subject: Re: is_uploaded_file() security
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-167106@lists.php.net to get a copy of this message
From: "Alexander Mueller" <alexm@gmx.at> > AFAIK the browser only sends the content of the chosen file and cannot > specify in any way a local filename which should be worked on. > Furthermore PHP creates a temporary file containing the uploaded file > content and passes this filename as 'tmp_name' variable. How can then a > "malicious user try to trick the script"? The user can pass the name of a file on the server. If you're not doing any checks and moving or displaying the "file" the user "sent" you, you may end up moving, deleting, or displaying any file on your server. ---John Holmes...

« previous php.general (#167106) next »