We use cookies to improve your experience. No personal information is gathered and we don't serve ads. Cookies Policy.

ExpressionEngine Logo ExpressionEngine
Features Pricing Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University
Log In or Sign Up
Log In Sign Up
ExpressionEngine Logo
Features Pro new Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University Blog
  • Home
  • Forums

FrontEnd file Upload - FreeForm how secure

Development and Programming

Neil Evans's avatar
Neil Evans
1,403 posts
16 years ago
Neil Evans's avatar Neil Evans

I create a FreeForm form on the front end and permit a file to be uploaded through it. This file follows the rules as set in my file upload preferences settings… so yes i can control the file type to images or all types. control the file size, the location, etc.

However, what other security is in place for these files? are certain file types crossed off the list for example, are the file extensions checked against the MIME types, if so are double extensions checked .jpg.php or .php.jpg, etc…

in the case of MIME types, where are these defined as i have a funny MS Word with DOC and DOCx will cause problems, etc! When upgrading will i have to redefine this or are these settings outside the upgrade files? etc?

lots of questions!!! and rambling!!! sorry, just want to be happy the file upload is safe as logically it can be. Thanks,

[Mod Edit: Moved to the Modules forum]

       
Neil Evans's avatar
Neil Evans
1,403 posts
16 years ago
Neil Evans's avatar Neil Evans

i understand why you moved this… because it relates to freeform…

but the question is about how secure the upload is as free form uses EE to handle the file???

       

Reply

Sign In To Reply

ExpressionEngine Home Features Pro Contact Version Support
Learn Docs University Forums
Resources Support Add-Ons Partners Blog
Privacy Terms Trademark Use License

Packet Tide owns and develops ExpressionEngine. © Packet Tide, All Rights Reserved.