note 92724 added to features.file-upload

From: Date: Thu, 06 Aug 2009 05:15:41 +0000
Subject: note 92724 added to features.file-upload
Groups: php.notes 
Request: Send a blank email to php-notes+get-159138@lists.php.net to get a copy of this message
I needed to quickly patch a server with a lot of bad file upload code (multiple sites). Here's what I came up with. Paste this in every PHP file on the server that contains $_FILE before the first reference of $_FILE: // begin Dave B's Q&D file upload security code $allowedExtensions = array("txt","csv","htm","html","xml", "css","doc","xls","rtf","ppt","pdf","swf","flv","avi", "wmv","mov","jpg","jpeg","gif","png"); foreach ($_FILES as $file) { if ($file['tmp_name'] > '') { if (!in_array(end(explode(".", strtolower($file['name']))), $allowedExtensions)) { die($file['name'].' is an invalid file type!<br/>'. '<a href="javascript:history.go(-1);">'. '&lt;&lt Go Back</a>'); } } } // end Dave B's Q&D file upload security code ---- Server IP: 209.41.74.194 Probable Submitter: 69.76.207.117 ---- Manual Page -- http://www.php.net/manual/en/features.file-upload.php Edit -- https://master.php.net/note/edit/92724 Del: integrated -- https://master.php.net/note/delete/92724/integrated Del: useless -- https://master.php.net/note/delete/92724/useless Del: bad code -- https://master.php.net/note/delete/92724/bad+code Del: spam -- https://master.php.net/note/delete/92724/spam Del: non-english -- https://master.php.net/note/delete/92724/non-english Del: in docs -- https://master.php.net/note/delete/92724/in+docs Del: other reasons-- https://master.php.net/note/delete/92724 Reject -- https://master.php.net/note/reject/92724 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#159138) next »