Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:12634 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 31451 invoked by uid 1010); 7 Sep 2004 18:15:15 -0000 Delivered-To: ezmlm-scan-internals@lists.php.net Delivered-To: ezmlm-internals@lists.php.net Received: (qmail 21644 invoked from network); 7 Sep 2004 18:14:22 -0000 Received: from unknown (HELO e-matters.de) (217.69.76.213) by pb1.pair.com with SMTP; 7 Sep 2004 18:14:22 -0000 Received: (qmail 14454 invoked by uid 0); 7 Sep 2004 18:11:18 -0000 Received: from p54875e53.dip.t-dialin.net (HELO ?192.168.1.77?) (84.135.94.83) by /var/run/qmail-smtp.pid with SMTP; 7 Sep 2004 18:11:18 -0000 Message-ID: <413DFA6C.1070705@php.net> Date: Tue, 07 Sep 2004 20:14:04 +0200 User-Agent: Mozilla Thunderbird 0.7.2 (Windows/20040707) X-Accept-Language: en-us, en MIME-Version: 1.0 To: internals@lists.php.net Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit Subject: PHP Documentation Problem 100th time From: sesser@php.net (Stefan Esser) Hi, I just realised that Example 34-2. Validating file uploads Is still showing a bullshit example. It constructs a destination path for move_uploaded_file() that consists of user input. There is no sanity check on it like removing / and .. sequences. Can one of the DOC guys finally fix this code? Stefan Esser