多文件上传移动失败求助:无法将图片移至指定文件夹
Let's walk through the key issues in your code that are preventing images from being moved to the specified folder, along with practical fixes:
1. Wrongly Accessing Uploaded Files (Using $_POST Instead of $_FILES)
When handling file uploads with <input type="file" name="aipicture[]" multiple>, all file-related data lives in the $_FILES superglobal—not $_POST. Your current code tries to pull $aipicture = $_POST['aipicture']; which will return an empty value or null, breaking every step that follows.
2. Incomplete Target Path for move_uploaded_file
The move_uploaded_file function requires a full target path that includes the filename. Right now you're only passing ../img, which tells PHP to move the file to the folder but not what to name it. This will cause the function to fail silently in most environments.
3. (Potential) Folder Permissions
Double-check that the ../img directory has proper write permissions for the web server user (e.g., www-data on Apache). Without this, PHP won’t be able to save files to the folder. You can set safe permissions via command line:
chmod 755 ../img
Avoid using 777 as it poses a critical security risk.
4. SQL Injection Vulnerability (Bonus Critical Fix)
Your current SQL query directly inserts user-submitted data into the database, which is a major security hole. Always use prepared statements to prevent injection attacks.
Fixed PHP Code
Here's the revised code addressing all the above issues:
if(isset($_POST['aisubmit'])) { $aialbum = $_POST['aialbum']; // Access uploaded files from $_FILES, not $_POST $uploadedFiles = $_FILES['aipicture']; $fileCount = count($uploadedFiles['name']); for($i = 0; $i < $fileCount; $i++) { // Skip empty entries if user didn't select a file if(empty($uploadedFiles['name'][$i])) continue; $tempName = $uploadedFiles['tmp_name'][$i]; $orgName = $uploadedFiles['name'][$i]; // Append filename to target path to define full save location $targetPath = "../img/" . basename($orgName); // Verify the file was uploaded correctly before moving if(is_uploaded_file($tempName)) { if(move_uploaded_file($tempName, $targetPath)) { // Use prepared statement to eliminate SQL injection risk $sql = "INSERT INTO cms_album_photos (album_name, picture) VALUES (?, ?)"; $stmt = mysqli_prepare($con, $sql); $picturePath = "img/" . basename($orgName); mysqli_stmt_bind_param($stmt, "ss", $aialbum, $picturePath); mysqli_stmt_execute($stmt); } else { // Optional: Log failed moves for debugging error_log("Failed to move file: " . $orgName); } } } // Redirect logic remains unchanged echo '<script type="text/javascript">'; echo 'window.location.href="home.php";'; echo '</script>'; echo '<noscript>'; echo '<meta http-equiv="refresh" content="0;url=home.php" />'; echo '</noscript>'; exit; }
Key Changes Explained:
- Switched from
$_POST['aipicture']to$_FILES['aipicture']to access actual upload metadata - Added the filename to
$targetPathso PHP knows exactly where to save each file - Added
is_uploaded_file()to validate that the file came from a legitimate upload - Implemented prepared statements for the SQL query to block injection attacks
- Added basic error logging to help debug any remaining upload failures
内容的提问来源于stack exchange,提问作者G. Joaquin

