|  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #9144 /tmp/php?????? file created without reference in POST array
Submitted: 2001-02-07 06:29 UTC Modified: 2001-02-14 06:32 UTC
From: david at littlesystems dot com dot au Assigned:
Status: Closed Package: Filesystem function related
PHP Version: 4.0.3pl1 OS: SuSE Linux 7.0
Private report: No CVE-ID: None
 [2001-02-07 06:29 UTC] david at littlesystems dot com dot au
Example HTML file upload form:
<FORM ENCTYPE="multipart/form-data" ACTION="./phpscript.php" METHOD=POST>
<INPUT NAME="myfile" TYPE="file">
<INPUT TYPE="submit">

If a user puts a false reference to a file in that filebox and then clicks the submit button, a "/tmp/php??????" temp file is actually created. But, the reference to that temp file in the HTTP_POST_FILES["myfile"]["tmp_name"] says "none". This means you cannot unlink() these files normally.

Configure line: './configure' '--with-apxs' '--with-pgsql=/var/lib/pgsql' '--enable-track-vars' '--with-ftp' '--enable-trans-sid'



Add a Patch

Pull Requests

Add a Pull Request


AllCommentsChangesGit/SVN commitsRelated reports
 [2001-02-14 06:32 UTC]
The files are of 0 bytes long and are deleted after script finishes by PHP itself.
The cleaning should work in 4.0.4pl1 so please upgrade.


PHP Copyright © 2001-2024 The PHP Group
All rights reserved.
Last updated: Mon Feb 26 20:01:28 2024 UTC