【发布时间】:2011-12-05 17:29:51
【问题描述】:
我正在尝试实现一个提交系统,人们可以在其中填写个人信息并附加文件上传。他们的信息应记录到 MySQL 数据库中,文件应重命名为其中一个字段,然后是扩展名。这是我到目前为止所拥有的..
这是表单页面:
<html>
<head>
<title>Submissions Script DEV</title>
<style type="text/css">
/**** Start page styles ****/
body {
background: #DFA01B;
font-family: arial, sans-serif;
font-size: 14px;
}
#wrap {
max-width: 600px;
margin: 30px auto;
background: #fff;
border: 4px solid #FFD16F;
-moz-border-radius: 15px;
-webkit-border-radius: 15px;
border-radius: 15px;
padding: 20px;
}
</style>
<body>
<div id="wrap">
<div align="center">
<a href="http://siteurl.com"><img src="logo.png" /> </a>
<h1 style="font-family:arial">Submissions</h1>
<p style="font-family:helvetica"> <i> Welcome to the submission page</i> </p>
</div>
<form method="POST" action="upload.php" enctype="multipart/form-data">
<p>
Please enter your first name: <input type="text" name = "fname">
<p>
Please enter your last name: <input type="text" name= "lname">
<p>
Student #: <input type="text" name= "snumber"/>
<p>
Grade: <select name= "grade">
<option>9</option>
<option>10</option>
<option>11</option>
<option>12</option>
</select>
<p>
<hr>
<!---Upload file section begins--->
Please attach your Powerpoint (ppt/pptx/zip) file. The file should be named student#.zip. (For example; 123456.ppt)
</p>
<input type="hidden" name="size" value="1024000">
<input type="file" name="upload">
<p>
<br/>
<br/>
<div align="center">
<input type=button onClick="location.href='instructions.html'" value='Back'>
<input TYPE="submit" name="upload" title="Send your submission" value="Submit Portfolio"/>
</div>
</form>
<p>
<!---Footer Styling--->
<div style="font-family: Arial;
font-size: 10px;
color: grey;
align: center;">
<!---Footer Contents--->
<p>Copyright <a href="http://sitename.com">site</a>site</p>
</div>
</div>
</body>
</html>
这是upload.php:
<?php
//This is the directory where images will be saved
$target = "uploads/";
$target = $target . basename( $_FILES['upload']['name']);
//This gets all the other information from the form
$fname=$_POST['fname'];
$lname=$_POST['lname'];
$upload=($_FILES['upload']['name']);
$snumber=$_POST['snumber'];
$grade=$_POST['grade'];
// Connects to your Database
mysql_connect("localhost", "db_user", "dbuserpass") or die(mysql_error()) ;
mysql_select_db("sub-data") or die(mysql_error()) ;
//Writes the information to the database
mysql_query("INSERT INTO `Submissions` VALUES ('$fname', '$lname', '$snumber', '$grade', '$upload')") ;
//Writes the upload to the server
if(move_uploaded_file($_FILES['upload']['tmp_name'], $target))
{
//Tells you if its all ok
echo "The file ". basename( $_FILES['uploadedfile']['name']). " has been uploaded, and your information has been recorded";
}
else {
//Gives and error if its not
echo "Sorry, there was a problem uploading your file.";
}
?>
最后,我希望使用表单中的 snumber 字段来命名文件上传。例如,如果有人在 snumber 字段中填写了 12345 并上传了一个 .zip 文件,它应该自动重命名为 12345.zip 并存储在相应的目录中。
我该怎么做呢?我对 PHP 很陌生,但我已经做了一些与这个问题有关的研究,尽管我还没有找到任何适合这个需求的东西。
【问题讨论】:
-
你为什么不更新
$target? -
你这是什么意思?抱歉,对这一切真的很陌生。
-
您似乎在您的应用程序中写入了一些SQL Injection 漏洞。我建议学习如何使用PHP's prepared statements,这使得编写数据库代码对您和您的用户来说更加安全。另外,您可能已经写了Directory traversal vulnerability,因为我在这里看不到任何文件名清理。 (可能在
move_uploaded_file()?) -
是的,接下来我正在研究适当的安全性。我需要先让这个非常基本的功能正常工作,现在我正在研究安全性添加。
标签: php html forms file-upload upload