nerdexam
National_Instruments

200-500 · Question #134

An HTML form contains this form element: <input type="file" name="myFile" /> When this form is submitted, the following PHP code gets executed: 1 <?php 2 move_uploaded_file( 3…

The correct answer is B. Sanitize the file name in $_FILES['myFile']['name'] because this value is not consistent among D. Sanitize the file name in $_FILES['myFile']['name'] because this value could be forged. See the full explanation below for the reasoning.

Question

An HTML form contains this form element:

<input type="file" name="myFile" /> When this form is submitted, the following PHP code gets executed:

1 <?php 2 move_uploaded_file( 3 $_FILES['myFile']['tmp_name'], 4 'uploads/' . $_FILES['myFile']['name']); 5 ?> Which of the following actions must be taken before this code may go into production? (Choose 2)

Options

  • ACheck with is_uploaded_file() whether the uploaded file $_FILES['myFile']['tmp_name'] is valid
  • BSanitize the file name in $_FILES['myFile']['name'] because this value is not consistent among
  • CCheck the charset encoding of the HTTP request to see whether it matches the encoding of the
  • DSanitize the file name in $_FILES['myFile']['name'] because this value could be forged
  • EUse $HTTP_POST_FILES instead of $_FILES to maintain upwards compatibility

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    76% (13)
  • C
    6% (1)
  • E
    12% (2)

Community Discussion

No community discussion yet for this question.

Full 200-500 Practice