$_FILES['name'] check

From: Date: Sun, 16 Feb 2020 23:24:05 +0000
Subject: $_FILES['name'] check
Groups: php.internals 
Request: Send a blank email to internals+get-108624@lists.php.net to get a copy of this message
Hi, Just to check, at the moment, if I was an evil hacker, and was to run: curl -F 'file=@example.jpg;filename=../../../example.php' https://example.com/upload/ The $_FILES['file']['name'] would be set to "example.php", where PHP has removed the leading "../../../" (good to see). Does that happen simply because of this IE fix, where it uses _basename() in the PHP source: https://github.com/php/php-src/blob/0b4778c377a5753a0deb9cfc697d4f62acf93a29/main/rfc1867.c#L1144 Craig

« previous php.internals (#108624) next »