Re: is_uploaded_file() security

From: Date: Wed, 22 Oct 2003 17:02:50 +0000
Subject: Re: is_uploaded_file() security
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-167119@lists.php.net to get a copy of this message
"Cpt John W. Holmes" wrote: > > The user can pass the name of a file on the server. If you're not doing any > checks and moving or displaying the "file" the user "sent" you, you may end > up moving, deleting, or displaying any file on your server. > > ---John Holmes... Thanks John, but only in the case global variables are active (as Marek mentioned), right? Alexander -- PINO - The free Chatsystem! Available at http://www.pino.org

« previous php.general (#167119) next »