Re: is_uploaded_file() security
| From: | CPT John W. Holmes | Date: | Wed, 22 Oct 2003 15:46:32 +0000 |
| Subject: | Re: is_uploaded_file() security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-167106@lists.php.net to get a copy of this message | ||
From: "Alexander Mueller" <alexm@gmx.at>
> AFAIK the browser only sends the content of the chosen file and cannot
> specify in any way a local filename which should be worked on.
> Furthermore PHP creates a temporary file containing the uploaded file
> content and passes this filename as 'tmp_name' variable. How can then a
> "malicious user try to trick the script"?
The user can pass the name of a file on the server. If you're not doing any
checks and moving or displaying the "file" the user "sent" you, you may end
up moving, deleting, or displaying any file on your server.
---John Holmes...