note 92724 added to features.file-upload
| From: | dbennettNOSPAM at bensoft dot com | Date: | Thu, 06 Aug 2009 05:15:41 +0000 |
| Subject: | note 92724 added to features.file-upload | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-159138@lists.php.net to get a copy of this message | ||
I needed to quickly patch a server with a lot of bad file upload
code (multiple sites). Here's what I came up with. Paste this
in every PHP file on the server that contains $_FILE before the
first reference of $_FILE:
// begin Dave B's Q&D file upload security code
$allowedExtensions =
array("txt","csv","htm","html","xml",
"css","doc","xls","rtf","ppt","pdf","swf","flv","avi",
"wmv","mov","jpg","jpeg","gif","png");
foreach ($_FILES as $file) {
if ($file['tmp_name'] > '') {
if (!in_array(end(explode(".",
strtolower($file['name']))),
$allowedExtensions)) {
die($file['name'].' is an invalid file type!<br/>'.
'<a href="javascript:history.go(-1);">'.
'<< Go Back</a>');
}
}
}
// end Dave B's Q&D file upload security code
----
Server IP: 209.41.74.194
Probable Submitter: 69.76.207.117
----
Manual Page -- http://www.php.net/manual/en/features.file-upload.php
Edit -- https://master.php.net/note/edit/92724
Del: integrated -- https://master.php.net/note/delete/92724/integrated
Del: useless -- https://master.php.net/note/delete/92724/useless
Del: bad code -- https://master.php.net/note/delete/92724/bad+code
Del: spam -- https://master.php.net/note/delete/92724/spam
Del: non-english -- https://master.php.net/note/delete/92724/non-english
Del: in docs -- https://master.php.net/note/delete/92724/in+docs
Del: other reasons-- https://master.php.net/note/delete/92724
Reject -- https://master.php.net/note/reject/92724
Search -- https://master.php.net/manage/user-notes.php