note 92724 modified in features.file-upload by danbrown

From: Date: Thu, 06 Aug 2009 17:38:34 +0000
Subject: note 92724 modified in features.file-upload by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-159157@lists.php.net to get a copy of this message
I needed to quickly patch a server with a lot of bad file upload code (multiple sites). Here's what I came up with. Paste this in every PHP file on the server that contains $_FILE before the first reference of $_FILE: <?php // begin Dave B's Q&D file upload security code $allowedExtensions = array("txt","csv","htm","html","xml", "css","doc","xls","rtf","ppt","pdf","swf","flv","avi", "wmv","mov","jpg","jpeg","gif","png"); foreach ($_FILES as $file) { if ($file['tmp_name'] > '') { if (!in_array(end(explode(".", strtolower($file['name']))), $allowedExtensions)) { die($file['name'].' is an invalid file type!<br/>'. '<a href="javascript:history.go(-1);">'. '&lt;&lt Go Back</a>'); } } } // end Dave B's Q&D file upload security code ?> --was-- I needed to quickly patch a server with a lot of bad file upload code (multiple sites). Here's what I came up with. Paste this in every PHP file on the server that contains $_FILE before the first reference of $_FILE: // begin Dave B's Q&D file upload security code $allowedExtensions = array("txt","csv","htm","html","xml", "css","doc","xls","rtf","ppt","pdf","swf","flv","avi", "wmv","mov","jpg","jpeg","gif","png"); foreach ($_FILES as $file) { if ($file['tmp_name'] > '') { if (!in_array(end(explode(".", strtolower($file['name']))), $allowedExtensions)) { die($file['name'].' is an invalid file type!<br/>'. '<a href="javascript:history.go(-1);">'. '&lt;&lt Go Back</a>'); } } } // end Dave B's Q&D file upload security code http://php.net/manual/en/features.file-upload.php

« previous php.notes (#159157) next »