<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Gravity Support Forums Topic: Filter .php files on file upload</title>
		<link>https://legacy.forums.gravityhelp.com/topic/filter-php-files-on-file-upload</link>
		<description>Gravity Support Forums Topic: Filter .php files on file upload</description>
		<language>en-US</language>
		<pubDate>Sun, 19 Apr 2026 19:57:54 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.1</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>https://legacy.forums.gravityhelp.com/search.php</link>
		</textInput>
		<atom:link href="https://legacy.forums.gravityhelp.com/rss/topic/filter-php-files-on-file-upload" rel="self" type="application/rss+xml" />

		<item>
			<title>Carl Hancock on "Filter .php files on file upload"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/filter-php-files-on-file-upload#post-3673</link>
			<pubDate>Mon, 01 Mar 2010 19:06:35 +0000</pubDate>
			<dc:creator>Carl Hancock</dc:creator>
			<guid isPermaLink="false">3673@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;Very good point and I remember doing this already so i'm going to have to look into why it is no longer in place and we will certainly correct it in the next release.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>jhherren on "Filter .php files on file upload"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/filter-php-files-on-file-upload#post-3671</link>
			<pubDate>Mon, 01 Mar 2010 18:31:36 +0000</pubDate>
			<dc:creator>jhherren</dc:creator>
			<guid isPermaLink="false">3671@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;It seems dangerous to me that a user can upload a .php file through a file upload if no file extension are set, which is the default behavior for the file upload field. Since files are uploaded to an easily guessable path, this looks like a file inclusion vulnerability waiting to happen. &#60;/p&#62;
&#60;p&#62;I think you should consider filtering .php files (and .js, too) from being uploaded. Users wanting to submit .php files can package them in an archive such as a zip file.
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>
