Re: is_uploaded_file() security
| From: | Raditha Dissanayake | Date: | Thu, 23 Oct 2003 14:25:55 +0000 |
| Subject: | Re: is_uploaded_file() security | ||
| References: | 1 2 3 4 5 6 7 8 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-167278@lists.php.net to get a copy of this message | ||
hi,
I think marek's recent message has answered this already, but i also believe that even in the older system where
you have form fields like <input type="file" name="userfile"> result in global variables like userfile_name etc the global variables don't get populated unless you send the correct enctype.
best regards
Alexander Mueller wrote:
Raditha Dissanayake wrote:-- Raditha Dissanayake. ------------------------------------------------------------------------ http://www.radinks.com/sftp/ | http://www.raditha/megaupload/ Lean and mean Secure FTP applet with | Mega Upload - PHP file uploader Graphical User Inteface. Just 150 KB | with progress bar.Hi, Multipart/form-data sends the entire file, if you don't use that enctype yes, just the file name is sent. best regardsI see, but then $_FILES is probably not set. So it wouldnt be necessary to use is_uploaded_file() if one solely uses $_FILES (but should probably nevertheless for any possible bugs - as Marek mentioned). Did I miss anything? Alexander