Re: is_uploaded_file() security
| From: | Alexander Mueller | Date: | Thu, 23 Oct 2003 14:11:34 +0000 |
| Subject: | Re: is_uploaded_file() security | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-167273@lists.php.net to get a copy of this message | ||
Raditha Dissanayake wrote:
>
> Hi,
> Multipart/form-data sends the entire file, if you don't use that enctype
> yes, just the file name is sent.
>
> best regards
I see, but then $_FILES is probably not set. So it wouldnt be necessary
to use is_uploaded_file() if one solely uses $_FILES (but should
probably nevertheless for any possible bugs - as Marek mentioned). Did I
miss anything?
Alexander
--
PINO - The free Chatsystem!
Available at http://www.pino.org