note 48692 added to features.file-upload

From: Date: Tue, 04 Jan 2005 22:48:16 +0000
Subject: note 48692 added to features.file-upload
Groups: php.notes 
Request: Send a blank email to php-notes+get-82724@lists.php.net to get a copy of this message
Be sure to be careful with the $_FILES['userfile']['name'] array element. If the client uploads a file that has an apostrophe in the filename it WILL NOT get set to the full name of the file from the client's machine. For example, if the client uploads a file named george's car.jpg the $_FILES['userfile']['name'] element will be set to s car.jpg because PHP appears to cut off everything before the apostrophe as well as the apostrophe itself. This did not happen in some of the previous versions of PHP but I know that it happens in version 4.3.10 so watch out for this. I thought this was a bug so I submitted it but it turns out that it is a "security measure" ---- Manual Page -- http://www.php.net/manual/en/features.file-upload.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+48692 Delete -- http://master.php.net/manage/user-notes.php?action=delete+48692&report=yes Reason: bad code -- http://master.php.net/manage/user-notes.php?action=delete+48692&report=yes&reason=bad+code Reason: spam -- http://master.php.net/manage/user-notes.php?action=delete+48692&report=yes&reason=spam Reason: useless example -- http://master.php.net/manage/user-notes.php?action=delete+48692&report=yes&reason=useless+example Reason: contains commercial links -- http://master.php.net/manage/user-notes.php?action=delete+48692&report=yes&reason=contains+commercial+links Reason: useless note -- http://master.php.net/manage/user-notes.php?action=delete+48692&report=yes&reason=useless+note Reject -- http://master.php.net/manage/user-notes.php?action=reject+48692&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#82724) next »