note 78674 deleted from security.magicquotes by danbrown
| From: | danbrown@php.net | Date: | Fri, 13 Mar 2009 20:31:22 +0000 |
| Subject: | note 78674 deleted from security.magicquotes by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-151854@lists.php.net to get a copy of this message | ||
Note Submitter: Shaun
----
In my tests with $_FILE, I found that file uploading didn't work when it was included in the
function (Confirmed on Windows, not Apache.)
The problem caused is: It removes the trailing / from what I have the tmp directory defined as.
So: When PHP tries to move a tmp file using move_uploaded_file, it's trying to move tmpxxxx.tmp
Whereas it should be trying to move: tmp/xxxx.tmp
In conclusion:
I found it easiest just to leave the $_FILES array alone.
$_FILES works differently than $_POST anyway. It outputs an error if the file is invalid, so
I'm not sure how someone could inject bad code into the field.
If anyone else can check this problem on a Linux/Unix server, that would be great.