Jump to content

Recommended Posts

Posted

Link to a page on my website where PHP is getting executed even when the extension is random.1.2.3.

 

: Link

 

Is this the problem with the configuration of Apache with PHP ? Help needed. If I have uploading enabled and I am restricting PHP files then a attacker can upload a file with some other extension and execute PHP on my website.

 

Thanking You,

Yash Sodha

  • Like 1
Posted

That's strange, Stevie used to only execute PHP in files with the .php extension. In any case, it's probably most secure to filter files with PHP opening/closing tags in addition to filtering the extension.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...