RE: [PHP] File Uploading Security - Urgent please
| From: | Moritz Petersen | Date: | Thu, 11 Jan 2001 11:28:21 +0000 |
| Subject: | RE: [PHP] File Uploading Security - Urgent please | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-33961@lists.php.net to get a copy of this message | ||
$userfile_type
contains the MIME-type of the file. This is maybe more relieable then just
the extension...
Mo.
> if(ereg("jpg|jpeg|gif$",$userfile_name))
> {
> do something
> }
> else
> {
> this file is not allowed
> }
> This will check that the uploaded file has the correct extension.
>
> Where $userfile is the upload field name in the form
>
> M@
> > -----Original Message-----
> > From: Statbat [mailto:statbat@gem.net.pk]
> > Sent: 11 January 2001 11:00
> > To: PHP-General
> > Subject: [PHP] File Uploading Security - Urgent please
> >
> >
> > Hello,
> >
> > I am doing file uploading of only jpg file format, It first copys
> > in tmp directory then I copy it in main.... well you all know the
> > procedure... neways what I am concerned is how can I check that
> > the file in temp is correct file and is safe for me to copy it in
> > the main folder?
> >
> > Regards
> > Statbat
> >
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>