请问$_FILES 是否可以伪造,应该注意哪些安全问题;

WBOY
Release: 2016-06-23 13:40:38
Original
861 people have browsed it

1.
$_FILES 是用户浏览器提交的数据,用户是否可以恶意修改$_FILES数组?
  恶意: 上传的文件名会不会出现 特殊字符. 


回复讨论(解决方案)

完全可以把.

字符是可以的。
只是在windows下不行。

$_FILES 不可被用户修改
只有傻瓜才会直接使用上传的文件名

source:php.cn
Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn
Popular Tutorials
More>
Latest Downloads
More>
Web Effects
Website Source Code
Website Materials
Front End Template
About us Disclaimer Sitemap
php.cn:Public welfare online PHP training,Help PHP learners grow quickly!