note 92724 modified in features.file-upload by danbrown
| From: | danbrown@php.net | Date: | Thu, 06 Aug 2009 17:38:34 +0000 |
| Subject: | note 92724 modified in features.file-upload by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-159157@lists.php.net to get a copy of this message | ||
I needed to quickly patch a server with a lot of bad file upload
code (multiple sites). Here's what I came up with. Paste this
in every PHP file on the server that contains $_FILE before the
first reference of $_FILE:
<?php
// begin Dave B's Q&D file upload security code
$allowedExtensions =
array("txt","csv","htm","html","xml",
"css","doc","xls","rtf","ppt","pdf","swf","flv","avi",
"wmv","mov","jpg","jpeg","gif","png");
foreach ($_FILES as $file) {
if ($file['tmp_name'] > '') {
if (!in_array(end(explode(".",
strtolower($file['name']))),
$allowedExtensions)) {
die($file['name'].' is an invalid file type!<br/>'.
'<a href="javascript:history.go(-1);">'.
'<< Go Back</a>');
}
}
}
// end Dave B's Q&D file upload security code
?>
--was--
I needed to quickly patch a server with a lot of bad file upload
code (multiple sites). Here's what I came up with. Paste this
in every PHP file on the server that contains $_FILE before the
first reference of $_FILE:
// begin Dave B's Q&D file upload security code
$allowedExtensions =
array("txt","csv","htm","html","xml",
"css","doc","xls","rtf","ppt","pdf","swf","flv","avi",
"wmv","mov","jpg","jpeg","gif","png");
foreach ($_FILES as $file) {
if ($file['tmp_name'] > '') {
if (!in_array(end(explode(".",
strtolower($file['name']))),
$allowedExtensions)) {
die($file['name'].' is an invalid file type!<br/>'.
'<a href="javascript:history.go(-1);">'.
'<< Go Back</a>');
}
}
}
// end Dave B's Q&D file upload security code
http://php.net/manual/en/features.file-upload.php