in reply to File Upload To Selected Directory
Many will tell you not to allow the user to select filename/path for their upload. (You decide, and save their choices in a database to let them retrieve the file based on the "vitural" path they selected). In many cases though that's not practical. So make sure the filename is COMPLETELY safe for your system if you can't avoid using the user selections. This means:
You can see File Upload Security Question by Ovid for a more intensive analysis of how paranoid you need to be about security.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
RE (tilly) 2: File Upload To Selected Directory
by tilly (Archbishop) on Sep 26, 2000 at 21:04 UTC | |
by swiftone (Curate) on Sep 26, 2000 at 21:08 UTC | |
|
(Ovid - what Perlmonks can do for you) RE(2): File Upload To Selected Directory
by Ovid (Cardinal) on Sep 27, 2000 at 01:14 UTC |