note 31362 added to features.file-upload
| From: | php-general at lists dot php dot net | Date: | Fri, 18 Apr 2003 14:31:30 +0000 |
| Subject: | note 31362 added to features.file-upload | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-46784@lists.php.net to get a copy of this message | ||
You might want to replace all occurrences of
"$_FILES['userfile']['name']" with
"basename($_FILES['userfile']['name'])" or something similar to
prevent unauthorized directory traversal.
The example used in the manual would allow anyone to provide a 'name' with
'../'.
--
http://www.php.net/manual/en/features.file-upload.php
http://master.php.net/manage/user-notes.php?action=edit+31362
http://master.php.net/manage/user-notes.php?action=delete+31362
http://master.php.net/manage/user-notes.php?action=reject+31362