note 92724 deleted from features.file-upload by googleguy
| From: | googleguy@php.net | Date: | Tue, 22 Oct 2013 06:48:20 +0000 |
| Subject: | note 92724 deleted from features.file-upload by googleguy | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-196652@lists.php.net to get a copy of this message | ||
Note Submitter: dbennettNOSPAM at bensoft dot com
----
I needed to quickly patch a server with a lot of bad file upload
code (multiple sites). Here's what I came up with. Paste this
in every PHP file on the server that contains $_FILE before the
first reference of $_FILE:
<?php
// begin Dave B's Q&D file upload security code
$allowedExtensions =
array("txt","csv","htm","html","xml",
"css","doc","xls","rtf","ppt","pdf","swf","flv","avi",
"wmv","mov","jpg","jpeg","gif","png");
foreach ($_FILES as $file) {
if ($file['tmp_name'] > '') {
if (!in_array(end(explode(".",
strtolower($file['name']))),
$allowedExtensions)) {
die($file['name'].' is an invalid file type!<br/>'.
'<a href="javascript:history.go(-1);">'.
'<< Go Back</a>');
}
}
}
// end Dave B's Q&D file upload security code
?>