Re: PHP Documentation Problem 100th time

From: Date: Wed, 08 Sep 2004 00:15:40 +0000
Subject: Re: PHP Documentation Problem 100th time
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-12641@lists.php.net to get a copy of this message
Stefan Esser wrote:
Example 34-2. Validating file uploads Is still showing a bullshit example. It constructs a destination path for move_uploaded_file() that consists of user input. There is no sanity check on it like removing / and .. sequences.
Would you agree that aplying basename() would be ok as a quick fix? $uploadfile .= basename($_FILES['userfile']['name']); instead of $uploadfile = $uploaddir . $_FILES['userfile']['name']; ? (in the long run i should voluntere to rewrite this, folding in information of my former magazine article on securing uploads ...) -- Hartmut Holzgraefe <hartmut@php.net>

« previous php.internals (#12641) next »