Re: verifying uploaded images
| From: | Matt McClanahan | Date: | Mon, 24 Jul 2000 02:29:26 +0000 |
| Subject: | Re: verifying uploaded images | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-7808@lists.php.net to get a copy of this message | ||
On Sun, 23 Jul 2000, Generic Player wrote:
> I have a form so people can upload images, which are then displayed with
> any posts they make on the message board. Question is, is there a way
> to verify wether or not the image.jpg they uploaded is actually a jpeg
> and not another type of file renamed, and will it matter? Is there any
> way that a malicious script of some sort could be uploaded in that way
> and run?
Any file uploads using an html form that PHP processes will have a few
standard variables set. They're detailed at
http://zend.php.net/manual/features.file-upload.php
The gist of it is that if you have an input tag such as
<input type=file name=myfile>
you'll have the following PHP variables set in the script that handles the
form action.
$myfile is the name of the temporary file on the server
$myfile_size is its size
$myfile_type is its mime type (The type(s) you care about are image/jpeg
and possibly image/pjpeg)
$myfile_name is the actual name of the file that was uploaded
So, on the form action PHP script, check $myfile_type against whatever
types you want to allow.
Matt