note 31362 deleted from features.file-upload by vincent
| From: | vincent@php.net | Date: | Fri, 12 Sep 2003 13:17:01 +0000 |
| Subject: | note 31362 deleted from features.file-upload by vincent | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-56382@lists.php.net to get a copy of this message | ||
Note Submitter:
----
You might want to replace all occurrences of
"$_FILES['userfile']['name']" with
"basename($_FILES['userfile']['name'])" or something similar to
prevent unauthorized directory traversal.
The example used in the manual would allow anyone to provide a 'name' with
'../'.