2008年10月28日星期二

[fw-mvc] Security concerns related to Zend_File

Hi,

I have some questions related to Zend_File validators:

1. After an upload using Zend_Form_Element_File there is any validation
of uploaded file name ? To not contain some kind of illegal characters

2. FileSize / Size validators are also validating size in relation with
ini_get('post_max_size') or $_SERVER['CONTENT_LENGTH'] or tio be sure
file is validated against 0 or negative file size ?

Thanks.

--
Best regards,
Cristian Bichis
www.zftutorials.com | www.zfforums.com | www.zftalk.com | ww.zflinks.com

没有评论: