search
HomeBackend DevelopmentPHP TutorialComplete explanation of PHP vulnerabilities (9)-File upload vulnerability

Please indicate the source for reprinting: PHP Vulnerability Complete Solution (9) - File Upload Vulnerability

A set of web applications generally provide a file upload function to facilitate visitors to upload some files.

Below is a simple file upload form



form>


php configuration file php.ini, the option upload_max_filesize specifies the file size allowed to be uploaded, the default is 2M

$_FILES array variable

PHP uses the variable $_FILES to upload files, $_FILES is an array. If you upload test.txt, the contents of the $_FILES array are:




$FILES
Array
{
[file] => Array
{
[name] => test.txt //File name
[type] => text/plain //MIME type
[tmp_name] => /tmp/php5D.tmp //Temporary file
[error] => 0 //Error message
[size] => 536 //File size, unit bytes
}
}
If the name attribute value of the upload file button is file


Then use $_FILES[' file']['name'] to get the name of the file uploaded by the client, excluding the path. Use $_FILES['file']['tmp_name'] to obtain the temporary file path where the server saves the uploaded file

The folder where the uploaded file is stored

PHP will not directly place the uploaded file in the root directory of the website, but Save as a temporary file, the name is the value of $_FILES['file']['tmp_name']. The developer must copy this temporary file to the website folder where it is stored.

The value of $_FILES['file']['tmp_name'] is set by PHP and is different from the original name of the file. Developers must use $_FILES['file']['name'] to obtain the value of the uploaded file. Original name.

Error information when uploading files

$_FILES['file']['error'] variable is used to save error information when uploading files. Its value is as follows:

Error information Value Description
UPLOAD_ERR_OK 0 No error
UPLOAD_ERR_INI_SIZE 1 The size of the uploaded file exceeds the php.ini setting
UPLO AD_ERR_FROM_SIZE 2 Upload file size exceeds HTML The value of MAX_FILE_SIZE in the form
UPLOAD_ERR_PARTIAL 3 Only upload part of the file
UPLOAD_ERR_NO_FILE 4 No file upload

File Upload Vulnerability

If you provide website visitors with the function of uploading images, you must be careful that what the visitor uploads may not actually be an image, but a PHP program that can be specified. If the directory where the images are stored is an open folder, the intruder can remotely execute the uploaded PHP file to carry out the attack.

The following is a simple file upload example:




php
// Set the directory for uploaded files
$uploaddir = "D:/www/images/";
// Check whether the file exists
if (isset ($_FILES['file1']))
{
// The full path to be placed in the website directory, including the file name
$uploadfile = $uploaddir . $_FILES['file1']['name'];
/ / Move the path stored on the server to the real file name
move_uploaded_file($_FILES['file1']['tmp_name'], $uploadfile);
}
?>
……






form>


This example does not check the file suffix, you can upload any file, it is very convenient Obvious upload vulnerability

The above is the complete explanation of PHP vulnerabilities (9) - File upload vulnerability. For more related content, please pay attention to the PHP Chinese website (www.php.cn)!


Statement
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn
What data can be stored in a PHP session?What data can be stored in a PHP session?May 02, 2025 am 12:17 AM

PHPsessionscanstorestrings,numbers,arrays,andobjects.1.Strings:textdatalikeusernames.2.Numbers:integersorfloatsforcounters.3.Arrays:listslikeshoppingcarts.4.Objects:complexstructuresthatareserialized.

How do you start a PHP session?How do you start a PHP session?May 02, 2025 am 12:16 AM

TostartaPHPsession,usesession_start()atthescript'sbeginning.1)Placeitbeforeanyoutputtosetthesessioncookie.2)Usesessionsforuserdatalikeloginstatusorshoppingcarts.3)RegeneratesessionIDstopreventfixationattacks.4)Considerusingadatabaseforsessionstoragei

What is session regeneration, and how does it improve security?What is session regeneration, and how does it improve security?May 02, 2025 am 12:15 AM

Session regeneration refers to generating a new session ID and invalidating the old ID when the user performs sensitive operations in case of session fixed attacks. The implementation steps include: 1. Detect sensitive operations, 2. Generate new session ID, 3. Destroy old session ID, 4. Update user-side session information.

What are some performance considerations when using PHP sessions?What are some performance considerations when using PHP sessions?May 02, 2025 am 12:11 AM

PHP sessions have a significant impact on application performance. Optimization methods include: 1. Use a database to store session data to improve response speed; 2. Reduce the use of session data and only store necessary information; 3. Use a non-blocking session processor to improve concurrency capabilities; 4. Adjust the session expiration time to balance user experience and server burden; 5. Use persistent sessions to reduce the number of data read and write times.

How do PHP sessions differ from cookies?How do PHP sessions differ from cookies?May 02, 2025 am 12:03 AM

PHPsessionsareserver-side,whilecookiesareclient-side.1)Sessionsstoredataontheserver,aremoresecure,andhandlelargerdata.2)Cookiesstoredataontheclient,arelesssecure,andlimitedinsize.Usesessionsforsensitivedataandcookiesfornon-sensitive,client-sidedata.

How does PHP identify a user's session?How does PHP identify a user's session?May 01, 2025 am 12:23 AM

PHPidentifiesauser'ssessionusingsessioncookiesandsessionIDs.1)Whensession_start()iscalled,PHPgeneratesauniquesessionIDstoredinacookienamedPHPSESSIDontheuser'sbrowser.2)ThisIDallowsPHPtoretrievesessiondatafromtheserver.

What are some best practices for securing PHP sessions?What are some best practices for securing PHP sessions?May 01, 2025 am 12:22 AM

The security of PHP sessions can be achieved through the following measures: 1. Use session_regenerate_id() to regenerate the session ID when the user logs in or is an important operation. 2. Encrypt the transmission session ID through the HTTPS protocol. 3. Use session_save_path() to specify the secure directory to store session data and set permissions correctly.

Where are PHP session files stored by default?Where are PHP session files stored by default?May 01, 2025 am 12:15 AM

PHPsessionfilesarestoredinthedirectoryspecifiedbysession.save_path,typically/tmponUnix-likesystemsorC:\Windows\TemponWindows.Tocustomizethis:1)Usesession_save_path()tosetacustomdirectory,ensuringit'swritable;2)Verifythecustomdirectoryexistsandiswrita

See all articles

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

MinGW - Minimalist GNU for Windows

MinGW - Minimalist GNU for Windows

This project is in the process of being migrated to osdn.net/projects/mingw, you can continue to follow us there. MinGW: A native Windows port of the GNU Compiler Collection (GCC), freely distributable import libraries and header files for building native Windows applications; includes extensions to the MSVC runtime to support C99 functionality. All MinGW software can run on 64-bit Windows platforms.

EditPlus Chinese cracked version

EditPlus Chinese cracked version

Small size, syntax highlighting, does not support code prompt function

Atom editor mac version download

Atom editor mac version download

The most popular open source editor

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 English version

SublimeText3 English version

Recommended: Win version, supports code prompts!