Welcome Guest, Not a member yet? Register   Sign In
Directory Traversal - sanitize_filename()
#2

[eluser]echo_boom[/eluser]
Does the danger from directory traversal come from PROCESSING an unsafe filename OR does the danger come from STORING an unsafe filename as it was originally named?

For example: if someone were to try and upload an image with an unsafe filename, and you simply renamed it, is everything ok? OR do you have to sanitize the filename BEFORE you rename it or do any kind of processing?


Messages In This Thread
Directory Traversal - sanitize_filename() - by El Forum - 11-05-2012, 07:32 PM
Directory Traversal - sanitize_filename() - by El Forum - 11-06-2012, 05:12 AM



Theme © iAndrew 2016 - Forum software by © MyBB