note 87188 added to function.getimagesize
| From: | anonymous at osu1 dot php dot net | Date: | Sun, 23 Nov 2008 16:30:55 +0000 |
| Subject: | note 87188 added to function.getimagesize | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-146845@lists.php.net to get a copy of this message | ||
Note that if you specify a remote file (via a URL) to check the size of, PHP will first download the
remote file to your server.
If you're using this function to check the size of user provided image links, this could
constitute a security risk. A malicious user could potentially link to a very large image file and
cause PHP to download it. I do not know what, if any, file size limits are in place for the
download. But suppose the user provided a link to an image that was several gigabytes in size?
It would be nice if there were a way to limit the size of the download performed by this function.
Hopefully there is already a default with some sensible limits.
----
Server IP: 209.41.74.194
Probable Submitter: 173.64.218.123
----
Manual Page -- http://www.php.net/manual/en/function.getimagesize.php
Edit -- https://master.php.net/note/edit/87188
Del: integrated -- https://master.php.net/note/delete/87188/integrated
Del: useless -- https://master.php.net/note/delete/87188/useless
Del: bad code -- https://master.php.net/note/delete/87188/bad+code
Del: spam -- https://master.php.net/note/delete/87188/spam
Del: non-english -- https://master.php.net/note/delete/87188/non-english
Del: in docs -- https://master.php.net/note/delete/87188/in+docs
Del: other reasons-- https://master.php.net/note/delete/87188
Reject -- https://master.php.net/note/reject/87188
Search -- https://master.php.net/manage/user-notes.php