|  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #50314 File upload problem with typo in form
Submitted: 2009-11-27 14:20 UTC Modified: 2016-08-07 18:07 UTC
Avg. Score:4.0 ± 1.0
Reproduced:2 of 2 (100.0%)
Same Version:1 (50.0%)
Same OS:0 (0.0%)
From: jj07020 at lanet dot lv Assigned: cmb (profile)
Status: Duplicate Package: *General Issues
PHP Version: 5.*, 6 OS: Windows XP Pro SP3
Private report: No CVE-ID: None
View Add Comment Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
You can add a comment by following this link or if you reported this bug, you can edit this bug over here.
Block user comment
Status: Assign to:
Bug Type:
From: jj07020 at lanet dot lv
New email:
PHP Version: OS:


 [2009-11-27 14:20 UTC] jj07020 at lanet dot lv
It is possible to supply a filename which will be incorrectly parsed by PHP. The problem occurs when uploading a file from an HTML form with attributes name="file[" (lacking the closing bracket) and type="file". I'm using Apache 2.2.14 & PHP 5.3.1, but I was able to reproduce the bug with Apache 2.2.10 & PHP 5.3.0.

Reproduce code:
HTML form - form.html:

<form method="post" enctype="multipart/form-data" action="upload.php">
<input type="file" name="file[" />
<input type="submit" value="OK" />

PHP code - upload.php:


The body of the HTTP request:

Content-Disposition: form-data; name="file["; filename="code.gif"
Content-Type: image/gif

<binary gif data>


Expected result:
The array $_FILES should contain valid keys as specified in Hovever, the following assertion fails:

if (isset($_FILES["file"])) {
    assert(is_string($_FILES["name"])); // actual key is "[name"

Since the filename ("file[") lacks the closing bracket, it probably should be interpreted as a single file named "file[":

array(1) { ["file["]=> array(5) { ["name"]=> string(8) "code.gif" ["type"]=> string(9) "image/gif" ["tmp_name"]=> string(17) "C:\Temp\php3A.tmp" ["error"]=> int(0) ["size"]=> int(3342) } }

Actual result:
The array $_FILES:

array(1) { ["file"]=> array(5) { ["[name"]=> string(8) "code.gif" ["[type"]=> string(9) "image/gif" ["[tmp_name"]=> string(17) "C:\Temp\php3A.tmp" ["[error"]=> int(0) ["[size"]=> int(3342) } }


Add a Patch

Pull Requests

Add a Pull Request


AllCommentsChangesGit/SVN commitsRelated reports
 [2009-11-29 12:38 UTC] jj07020 at lanet dot lv
I tried it with php 5.2 (Snapshot Fri, 27 Nov 2009 11:41:38 +0000, Version: 5.2.12RC3-dev) and it produces the same result.
 [2009-11-30 16:10 UTC]
This is not specific to any SAPI, happens also with sapi/cgi/ from today.
 [2013-12-05 19:41 UTC]
See bug #48597
 [2016-08-07 18:07 UTC]
-Status: Verified +Status: Duplicate -Assigned To: +Assigned To: cmb
 [2016-08-07 18:07 UTC]
> See bug #48597

Actually, this report is a duplicate of the other report.
PHP Copyright © 2001-2018 The PHP Group
All rights reserved.
Last updated: Sun Nov 19 01:31:42 2017 UTC