Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Directory Traversal via PHP Multi-File Uploads (nealpoole.com)
8 points by wglb on Oct 3, 2011 | hide | past | favorite | 1 comment


Variables containing extra opening square brackets cause PHP to make a malformed $_FILES array? That's really a whopper bug they got there, but in the end it's really just a variant of "web developer believes the Content-Type supplied by the user's browser is correct" in terms of vulnerability. Both the file name and the content type must be considered unchecked user input and have to be sanitized anyway.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: