Re: is_uploaded_file() security
| From: | Alexander Mueller | Date: | Wed, 22 Oct 2003 17:02:50 +0000 |
| Subject: | Re: is_uploaded_file() security | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-167119@lists.php.net to get a copy of this message | ||
"Cpt John W. Holmes" wrote:
>
> The user can pass the name of a file on the server. If you're not doing any
> checks and moving or displaying the "file" the user "sent" you, you may end
> up moving, deleting, or displaying any file on your server.
>
> ---John Holmes...
Thanks John, but only in the case global variables are active (as Marek
mentioned), right?
Alexander
--
PINO - The free Chatsystem!
Available at http://www.pino.org