in reply to Scrubbing a local path in a file upload

You should chdir or use absolute paths. You should also limit what can appear in a filename, or better yet, generate your own filenames. You should also use -T taint
  • Comment on Re: Scrubbing a local path in a file upload