Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. Web Development
  3. Open a file from server

Open a file from server

Scheduled Pinned Locked Moved Web Development
questionphphtmldatabasecom
30 Posts 2 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B Bradml

    can you please email me the source code so i can see what is going on.


    Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.

    B Offline
    B Offline
    Bradml
    wrote on last edited by
    #21

    OK two problems that jump out at me from the scripts you sent is that you have a character before the first tag in the library and also you have a blank line at the end of it. Because of this it will send all headers down before you can modify them.


    Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.

    1 Reply Last reply
    0
    • B Bradml

      OK two problems that jump out at me from the scripts you sent is that you have a character before the first tag in the library and also you have a blank line at the end of it. Because of this it will send all headers down before you can modify them.


      Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.

      H Offline
      H Offline
      hiral_shah
      wrote on last edited by
      #22

      I can not open the file from server yet. Please tell me how can I open it??

      -------------------------------------------------------------------------------------------------- Hiral Shah India If you think that my question is good enough and can be helpful for other then don't forget to vote. :)

      B 1 Reply Last reply
      0
      • H hiral_shah

        I can not open the file from server yet. Please tell me how can I open it??

        -------------------------------------------------------------------------------------------------- Hiral Shah India If you think that my question is good enough and can be helpful for other then don't forget to vote. :)

        B Offline
        B Offline
        Bradml
        wrote on last edited by
        #23

        Ok I have been reading the function where you get data from the database. One thing that really strikes me is that you don't validate the data before you pass it to the database. This is incredibly important because otherwise people can execute any SQL commands they want (including stealing other people's files). Please go to http://www.phpsec.org[^] to learn more. I have now emailed you an updated copy of the script which should fix the problem you have but will not fix the security problem.


        Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.

        H B 7 Replies Last reply
        0
        • B Bradml

          Ok I have been reading the function where you get data from the database. One thing that really strikes me is that you don't validate the data before you pass it to the database. This is incredibly important because otherwise people can execute any SQL commands they want (including stealing other people's files). Please go to http://www.phpsec.org[^] to learn more. I have now emailed you an updated copy of the script which should fix the problem you have but will not fix the security problem.


          Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.

          H Offline
          H Offline
          hiral_shah
          wrote on last edited by
          #24

          With your changes if I am saving the file then it is giving me perfact result but as I choose Open option it is showing the result like: ÐÏࡱá>þÿ giþÿÿÿfÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ&yu ml;ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ&yu ml;ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿì¥Áq` ø¿óbjbjqPqP .2::óÿÿÿÿÿÿ¤HHHHHHHÐÔì+ì+ì+ì+,,4¤ ˜bjX,\,\,\,\,\,&‚, Ž,bbbbbbb$dhjf„=bH.\,\,..=bHH\,\,Rb000.²H\,H\,b0.b00 ^DHHß`\,L, P*ÍÎ\Çì+Ã.‚O_&bhb0˜bu_jîfE/ÄîfLß`îfHß`8–,Zð,@00-4d-­–,–,–,=b=b 0–,–,–,˜b....¤ ¤ ¤ ¤H¤¤ ¤ ¤ H\D ,ÌHHHHHHÿÿÿÿ Case Studies for abc.com Currently we have three cases in our web site. Case Study Format About the client Application target users Business sensitivity. System Before What the client want? The most important benefit we have is a satisfied client.   #RŽ–¨©¹ºÓü  , - . š ª ½ Ô Õ Û â æ ë     6 D G H I X Y Z óïëïçãëÙãÕãÑÍÑÉÅÁÑÕÉÕ½¹µ±µÑ±ÑɵŪ¹Õ¦’m&hS Çh¹lH56>*B*CJaJph™3f hCw‹56>*B*CJ aJ ph™3f&h¹lHhv”56>*B*CJ aJ ph™3fhv” hCw‹hCw‹h¹SdhöhCw‹hî7ñhU+h>\hdkàh«Zh•JÛhÅh¢{×h¢{×5>*h¢{×heBÕhÎh¢h6oh6oh6o5CJ$aJ$' !"#RSczŽ‘’“”•–¨©ºý. ] s ÷õõõõõõõíííèèèèèèèèèèààààà & FgdÅgd¢{× & FgdeBÕ$a$gd6oóýs ˆ « ½ Õ  6 7 8 9 : ; < = > ? @ A B C D E F G H Y Z ÷÷÷÷÷÷òòòòòòòòòòòòòòòòòòêågd¹lH & Fgdv”gdCw‹ & FgdÅZ a d  Ž   ‘ Ê Ë  † ‡ ˆ ‰ ± ² ³ À Á Â Ä Ú ìÚ̽µ­¥›ˆ„ˆ€ˆ€ˆ€rdrSKAhµ1hµ15>*hµ1hµ15 hGš56>*B*CJ aJ ph™3fhaWhaW6>*B*phÿhaWhGš6>*B*phÿhGšhÜZ% hGšhGšhághDû>*CJ aJ hághDû5>*h0{hDû5h8ÕhDû5hGšCJ aJ hS ÇhS Ç56>*CJaJh˜ƒh˜ƒ5CJ\aJ#hS ÇhS Ç56B*CJaJph™3f&hS ÇhS Ç56>*B* CJaJph€€Z Ž  Ë ² Á Â Û Ü # $   Äůר²¿)*úõõõõúúúíèßÚßßßÒÍĻĶgd¨bü„p^„pgd•2„ ^„ gd4Tgd¾y› & Fgd¾y›gdƒ6n„ ^„ gdƒ6ngd‘?½ & Fgd¹lHgdGšgd¹lHÚ Û Ü õ ù ! " # $ ´ Ó Ô Õ ÃÄÆÖרðøù')*?@AçùïâØÑÍÉžº¾º¾¶²¨¡¨–Ž–ƒ{–ƒ–wmf\U h‚p™h‚p™h‚p™5B*phÿ h‚p™h¨büh¨bü5B*phÿh¾y›h4TB*phh•2hM'ÒB*phhM'ÒB*phh•2h•2B*

          1 Reply Last reply
          0
          • B Bradml

            Ok I have been reading the function where you get data from the database. One thing that really strikes me is that you don't validate the data before you pass it to the database. This is incredibly important because otherwise people can execute any SQL commands they want (including stealing other people's files). Please go to http://www.phpsec.org[^] to learn more. I have now emailed you an updated copy of the script which should fix the problem you have but will not fix the security problem.


            Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.

            B Offline
            B Offline
            Bradml
            wrote on last edited by
            #25

            That is peculiar. There is one thing that jumps to mind, you haven't stated that the "Content-type" header is "application/pdf". Can you confirm if you have done this or not? You can check by stopping the file from going down and then printing the value of the $fileType variable. You could also try making sure that the file name ends in .pdf, this is very important on a windows machine.


            Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.

            1 Reply Last reply
            0
            • B Bradml

              Ok I have been reading the function where you get data from the database. One thing that really strikes me is that you don't validate the data before you pass it to the database. This is incredibly important because otherwise people can execute any SQL commands they want (including stealing other people's files). Please go to http://www.phpsec.org[^] to learn more. I have now emailed you an updated copy of the script which should fix the problem you have but will not fix the security problem.


              Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.

              B Offline
              B Offline
              Bradml
              wrote on last edited by
              #26

              That is peculiar. There is one thing that jumps to mind, you haven't stated that the "Content-type" header is "application/pdf". Can you confirm if you have done this or not? You can check by stopping the file from going down and then printing the value of the $fileType variable. You could also try making sure that the file name ends in .pdf, this is very important on a windows machine.


              Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.

              1 Reply Last reply
              0
              • B Bradml

                Ok I have been reading the function where you get data from the database. One thing that really strikes me is that you don't validate the data before you pass it to the database. This is incredibly important because otherwise people can execute any SQL commands they want (including stealing other people's files). Please go to http://www.phpsec.org[^] to learn more. I have now emailed you an updated copy of the script which should fix the problem you have but will not fix the security problem.


                Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.

                B Offline
                B Offline
                Bradml
                wrote on last edited by
                #27

                That is peculiar. There is one thing that jumps to mind, you haven't stated that the "Content-type" header is "application/pdf". Can you confirm if you have done this or not? You can check by stopping the file from going down and then printing the value of the $fileType variable. You could also try making sure that the file name ends in .pdf, this is very important on a windows machine.


                Brad Australian - Bradml on "MVP Status" If this was posted in a programming board please rate my answer

                1 Reply Last reply
                0
                • B Bradml

                  Ok I have been reading the function where you get data from the database. One thing that really strikes me is that you don't validate the data before you pass it to the database. This is incredibly important because otherwise people can execute any SQL commands they want (including stealing other people's files). Please go to http://www.phpsec.org[^] to learn more. I have now emailed you an updated copy of the script which should fix the problem you have but will not fix the security problem.


                  Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.

                  H Offline
                  H Offline
                  hiral_shah
                  wrote on last edited by
                  #28

                  As I am trying to upload a pdf file and I tried to get the type of it by $_FILES['browsefile']['type']; I am getting blank type for pdf. Is there anything different for pdf type:confused:??

                  -------------------------------------------------------------------------------------------------- Hiral Shah India If you think that my question is good enough and can be helpful for other then don't forget to vote. :)

                  1 Reply Last reply
                  0
                  • B Bradml

                    Ok I have been reading the function where you get data from the database. One thing that really strikes me is that you don't validate the data before you pass it to the database. This is incredibly important because otherwise people can execute any SQL commands they want (including stealing other people's files). Please go to http://www.phpsec.org[^] to learn more. I have now emailed you an updated copy of the script which should fix the problem you have but will not fix the security problem.


                    Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.

                    H Offline
                    H Offline
                    hiral_shah
                    wrote on last edited by
                    #29

                    As I am trying to upload a pdf file and I tried to get the type of it by $_FILES['browsefile']['type']; I am getting blank type for pdf. Is there anything different for pdf type??

                    -------------------------------------------------------------------------------------------------- Hiral Shah India If you think that my question is good enough and can be helpful for other then don't forget to vote. :)

                    1 Reply Last reply
                    0
                    • B Bradml

                      Ok I have been reading the function where you get data from the database. One thing that really strikes me is that you don't validate the data before you pass it to the database. This is incredibly important because otherwise people can execute any SQL commands they want (including stealing other people's files). Please go to http://www.phpsec.org[^] to learn more. I have now emailed you an updated copy of the script which should fix the problem you have but will not fix the security problem.


                      Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.

                      B Offline
                      B Offline
                      Bradml
                      wrote on last edited by
                      #30

                      Sometimes the browser will just not give the type. An easy way to determine it after it is uploaded is to try matching the extension (ie .pdf) to a certain format and then use that if type = null.


                      Brad Australian - Christian Graus on "Best books for VBscript" A big thick one, so you can whack yourself on the head with it.

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups