[Typo3] Enabling PHP file Extensions

Kraft Bernhard kraftb at kraftb.at
Thu Apr 7 22:07:23 CEST 2005


Miller, Eric A. wrote:
> Typo3 says that it allows PHP file extension files to be created or
> uploaded to FileAdmin directory, but when I create or attempt an upload
> it says Filetyle "php" not allowed.
> 
> Anyone else run into this problem ?

I wouldn't want to call it problem.

Allowing uploading of PHP files to your server opens up a big security hole.

Everbody who has access to the fileadmin can execute arbitrary scripts on the
server ... and read your db password modify everything in the database (not just
what he is allowed to) and everything without admin rights !!!!

But do it a your own risk.

Its:
[BE][fileDenyPattern]
in the Install tool.


may you recover your data,
Bernhard



More information about the TYPO3-english mailing list