I have a script that I have modified to upload image to mysql but I am concerned about the security risk envovled with allowing user to upload files to a mysql..
I've been trying to modify the php to include validation for a jpg and gif but to not avail could someone point me in the direction I need to move with a visual sample
Thank's as all way!
[PHP]
if(isset($_POST['upload']) && $_FILES['userfile']['size']> 0)
{
$fileName = $_FILES['userfile']['name'];
$tmpName = $_FILES['userfile']['tmp_name'];
$fileSize = $_FILES['userfile']['size'];
$fileType = $_FILES['userfile']['type'];
$fp = fopen($tmpName, 'r');
$content = fread($fp, filesize($tmpNa me));
$content = addslashes($con tent);
fclose($fp);
if(!get_magic_q uotes_gpc())
{
$fileName = addslashes($fil eName);
}
include '../../config.php';
include '../../opendb.php';
$query = "INSERT audio SET name='$fileName ', size='$fileSize ', type='$fileType ', content='$conte nt' WHERE username='$user name'";
mysql_query($qu ery) or die(your upload could be done file already exist');
include '../../closedb.php';
echo "<br>File $fileName uploaded";
}
[/PHP]
I've been trying to modify the php to include validation for a jpg and gif but to not avail could someone point me in the direction I need to move with a visual sample
Thank's as all way!
[PHP]
if(isset($_POST['upload']) && $_FILES['userfile']['size']> 0)
{
$fileName = $_FILES['userfile']['name'];
$tmpName = $_FILES['userfile']['tmp_name'];
$fileSize = $_FILES['userfile']['size'];
$fileType = $_FILES['userfile']['type'];
$fp = fopen($tmpName, 'r');
$content = fread($fp, filesize($tmpNa me));
$content = addslashes($con tent);
fclose($fp);
if(!get_magic_q uotes_gpc())
{
$fileName = addslashes($fil eName);
}
include '../../config.php';
include '../../opendb.php';
$query = "INSERT audio SET name='$fileName ', size='$fileSize ', type='$fileType ', content='$conte nt' WHERE username='$user name'";
mysql_query($qu ery) or die(your upload could be done file already exist');
include '../../closedb.php';
echo "<br>File $fileName uploaded";
}
[/PHP]
Comment