Open a file from server
-
can you please email me the source code so i can see what is going on.
Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.
OK two problems that jump out at me from the scripts you sent is that you have a character before the first tag in the library and also you have a blank line at the end of it. Because of this it will send all headers down before you can modify them.
Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.
-
OK two problems that jump out at me from the scripts you sent is that you have a character before the first tag in the library and also you have a blank line at the end of it. Because of this it will send all headers down before you can modify them.
Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.
I can not open the file from server yet. Please tell me how can I open it??
-------------------------------------------------------------------------------------------------- Hiral Shah India If you think that my question is good enough and can be helpful for other then don't forget to vote. :)
-
I can not open the file from server yet. Please tell me how can I open it??
-------------------------------------------------------------------------------------------------- Hiral Shah India If you think that my question is good enough and can be helpful for other then don't forget to vote. :)
Ok I have been reading the function where you get data from the database. One thing that really strikes me is that you don't validate the data before you pass it to the database. This is incredibly important because otherwise people can execute any SQL commands they want (including stealing other people's files). Please go to http://www.phpsec.org[^] to learn more. I have now emailed you an updated copy of the script which should fix the problem you have but will not fix the security problem.
Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.
-
Ok I have been reading the function where you get data from the database. One thing that really strikes me is that you don't validate the data before you pass it to the database. This is incredibly important because otherwise people can execute any SQL commands they want (including stealing other people's files). Please go to http://www.phpsec.org[^] to learn more. I have now emailed you an updated copy of the script which should fix the problem you have but will not fix the security problem.
Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.
With your changes if I am saving the file then it is giving me perfact result but as I choose Open option it is showing the result like: ÐÏࡱá>þÿ giþÿÿÿfÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ&yu ml;ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ&yu ml;ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿì¥Áq` ø¿óbjbjqPqP .2::óÿÿÿÿÿÿ¤HHHHHHHÐÔì+ì+ì+ì+,,4¤ ˜bjX,\,\,\,\,\,&‚, Ž,bbbbbbb$dhjf„=bH.\,\,..=bHH\,\,Rb000.²H\,H\,b0.b00 ^DHHß`\,L, P*ÍÎ\Çì+Ã.‚O_&bhb0˜bu_jîfE/ÄîfLß`îfHß`8–,Zð,@00-4d-–,–,–,=b=b 0–,–,–,˜b....¤ ¤ ¤ ¤H¤¤ ¤ ¤ H\D ,ÌHHHHHHÿÿÿÿ Case Studies for abc.com Currently we have three cases in our web site. Case Study Format About the client Application target users Business sensitivity. System Before What the client want? The most important benefit we have is a satisfied client. #RŽ–¨©¹ºÓü , - . š ª ½ Ô Õ Û â æ ë 6 D G H I X Y Z óïëïçãëÙãÕãÑÍÑÉÅÁÑÕÉÕ½¹µ±µÑ±ÑɵŪ¹Õ¦’m&hS Çh¹lH56>*B*CJaJph™3f hCw‹56>*B*CJ aJ ph™3f&h¹lHhv”56>*B*CJ aJ ph™3fhv” hCw‹hCw‹h¹SdhöhCw‹hî7ñhU+h>\hdkàh«Zh•JÛhÅh¢{×h¢{×5>*h¢{×heBÕhÎh¢h6oh6oh6o5CJ$aJ$' !"#RSczŽ‘’“”•–¨©ºý. ] s ÷õõõõõõõíííèèèèèèèèèèààààà & FgdÅgd¢{× & FgdeBÕ$a$gd6oóýs ˆ « ½ Õ 6 7 8 9 : ; < = > ? @ A B C D E F G H Y Z ÷÷÷÷÷÷òòòòòòòòòòòòòòòòòòêågd¹lH & Fgdv”gdCw‹ & FgdÅZ a d Ž ‘ Ê Ë † ‡ ˆ ‰ ± ² ³ À Á Â Ä Ú ìÚ̽µ¥›ˆ„ˆ€ˆ€ˆ€rdrSKAhµ1hµ15>*hµ1hµ15 hGš56>*B*CJ aJ ph™3fhaWhaW6>*B*phÿhaWhGš6>*B*phÿhGšhÜZ% hGšhGšhághDû>*CJ aJ hághDû5>*h0{hDû5h8ÕhDû5hGšCJ aJ hS ÇhS Ç56>*CJaJh˜ƒh˜ƒ5CJ\aJ#hS ÇhS Ç56B*CJaJph™3f&hS ÇhS Ç56>*B* CJaJph€€Z Ž Ë ² Á Â Û Ü # $ Äůר²¿)*úõõõõúúúíèßÚßßßÒÍĻĶgd¨bü„p^„pgd•2„ ^„ gd4Tgd¾y› & Fgd¾y›gdƒ6n„ ^„ gdƒ6ngd‘?½ & Fgd¹lHgdGšgd¹lHÚ Û Ü õ ù ! " # $ ´ Ó Ô Õ ÃÄÆÖרðøù')*?@AçùïâØÑÍÉžº¾º¾¶²¨¡¨–Ž–ƒ{–ƒ–wmf\U h‚p™h‚p™h‚p™5B*phÿ h‚p™h¨büh¨bü5B*phÿh¾y›h4TB*phh•2hM'ÒB*phhM'ÒB*phh•2h•2B*
-
Ok I have been reading the function where you get data from the database. One thing that really strikes me is that you don't validate the data before you pass it to the database. This is incredibly important because otherwise people can execute any SQL commands they want (including stealing other people's files). Please go to http://www.phpsec.org[^] to learn more. I have now emailed you an updated copy of the script which should fix the problem you have but will not fix the security problem.
Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.
That is peculiar. There is one thing that jumps to mind, you haven't stated that the
"Content-type"
header is"application/pdf".
Can you confirm if you have done this or not? You can check by stopping the file from going down and then printing the value of the $fileType variable. You could also try making sure that the file name ends in.pdf
, this is very important on a windows machine.
Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.
-
Ok I have been reading the function where you get data from the database. One thing that really strikes me is that you don't validate the data before you pass it to the database. This is incredibly important because otherwise people can execute any SQL commands they want (including stealing other people's files). Please go to http://www.phpsec.org[^] to learn more. I have now emailed you an updated copy of the script which should fix the problem you have but will not fix the security problem.
Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.
That is peculiar. There is one thing that jumps to mind, you haven't stated that the
"Content-type"
header is"application/pdf".
Can you confirm if you have done this or not? You can check by stopping the file from going down and then printing the value of the $fileType variable. You could also try making sure that the file name ends in.pdf
, this is very important on a windows machine.
Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.
-
Ok I have been reading the function where you get data from the database. One thing that really strikes me is that you don't validate the data before you pass it to the database. This is incredibly important because otherwise people can execute any SQL commands they want (including stealing other people's files). Please go to http://www.phpsec.org[^] to learn more. I have now emailed you an updated copy of the script which should fix the problem you have but will not fix the security problem.
Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.
That is peculiar. There is one thing that jumps to mind, you haven't stated that the
"Content-type"
header is"application/pdf".
Can you confirm if you have done this or not? You can check by stopping the file from going down and then printing the value of the $fileType variable. You could also try making sure that the file name ends in.pdf
, this is very important on a windows machine.
Brad Australian - Bradml on "MVP Status" If this was posted in a programming board please rate my answer
-
Ok I have been reading the function where you get data from the database. One thing that really strikes me is that you don't validate the data before you pass it to the database. This is incredibly important because otherwise people can execute any SQL commands they want (including stealing other people's files). Please go to http://www.phpsec.org[^] to learn more. I have now emailed you an updated copy of the script which should fix the problem you have but will not fix the security problem.
Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.
As I am trying to upload a pdf file and I tried to get the type of it by $_FILES['browsefile']['type']; I am getting blank type for pdf. Is there anything different for pdf type:confused:??
-------------------------------------------------------------------------------------------------- Hiral Shah India If you think that my question is good enough and can be helpful for other then don't forget to vote. :)
-
Ok I have been reading the function where you get data from the database. One thing that really strikes me is that you don't validate the data before you pass it to the database. This is incredibly important because otherwise people can execute any SQL commands they want (including stealing other people's files). Please go to http://www.phpsec.org[^] to learn more. I have now emailed you an updated copy of the script which should fix the problem you have but will not fix the security problem.
Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.
As I am trying to upload a pdf file and I tried to get the type of it by $_FILES['browsefile']['type']; I am getting blank type for pdf. Is there anything different for pdf type??
-------------------------------------------------------------------------------------------------- Hiral Shah India If you think that my question is good enough and can be helpful for other then don't forget to vote. :)
-
Ok I have been reading the function where you get data from the database. One thing that really strikes me is that you don't validate the data before you pass it to the database. This is incredibly important because otherwise people can execute any SQL commands they want (including stealing other people's files). Please go to http://www.phpsec.org[^] to learn more. I have now emailed you an updated copy of the script which should fix the problem you have but will not fix the security problem.
Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.
Sometimes the browser will just not give the type. An easy way to determine it after it is uploaded is to try matching the extension (ie .pdf) to a certain format and then use that if type = null.
Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.