Re: is_uploaded_file() security
| From: | Marek Kilimajer | Date: | Thu, 23 Oct 2003 14:05:04 +0000 |
| Subject: | Re: is_uploaded_file() security | ||
| References: | 1 2 3 4 5 6 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-167271@lists.php.net to get a copy of this message | ||
I tried:
<form action="phpinfo.php?_FILES[fake][tmp_name]=/etc/passwd" method="post" enctype="multipart/form-data">
Fake: <input type="text" name="_FILES[fake][tmp_name]" value="/etc/passwd"><br>
<input type="file" name="subor"><br>
<input type="submit">
</form>
$_FILES superglobal still wasn't poisoned.
Alexander Mueller wrote:
Raditha Dissanayake wrote:This does not work with multipart/form-data you need www-urlencoded (or just don't set an enctype attribute in your form)What would happen in this case? The given filename would be passed to the script?! Alexander