Re: is_uploaded_file() security

From: Date: Thu, 23 Oct 2003 13:54:50 +0000
Subject: Re: is_uploaded_file() security
References: 1 2 3 4  Groups: php.general 
Request: Send a blank email to php-general+get-167266@lists.php.net to get a copy of this message
I don't think so. Test this, but I think you can just type /etc/passwd into the file name box (instead of using the "browse" button) and have that value submitted in the form. May be dependent upon the browser on how it's handled, though. This does not work with multipart/form-data you need www-urlencoded (or just don't set an enctype attribute in your form)
Either way, I can still construct a POST to your site using cURL or something to "simulate" sending you a file with a name of a file on your server. So, validate that the file is actually an uploaded file and not a path to something else. That's why the functions exist. ---John Holmes...
-- Raditha Dissanayake. ------------------------------------------------------------------------ http://www.radinks.com/sftp/ | http://www.raditha/megaupload/ Lean and mean Secure FTP applet with | Mega Upload - PHP file uploader Graphical User Inteface. Just 150 KB | with progress bar.

« previous php.general (#167266) next »