[TYPO3] does tt news accept exe and php (malicious) mime types ?

Dmitry Dulepov dmitry at typo3.org
Wed Jun 13 21:19:44 CEST 2007


Hi!

dave typo wrote:
> Could a user potentially upload an exe file or a php file using
> ttnews' file attachment property?

Take a look to near the upload box. You will see what it allows to 
upload and what does not (with "-" in front).

It does not use mme types but checks extensions.

-- 
Dmitry Dulepov
TYPO3 freelancer / TYPO3 core team member
Web: http://typo3bloke.net/
Skype: callto:liels_bugs


More information about the TYPO3-english mailing list