File upload security is more than extension checking
Checking the extension establishes almost nothing, because the name is chosen by whoever uploads it.
What matters is what the server does with the file: where it is stored, whether that location can execute anything, what the content actually is, and whether it is served back with a type that makes the browser run it. Most upload flaws are about handling rather than about the check at the door.
More on Web application security
- CSRF abuses an authenticated browserTheir note, your session
- XSS turns trusted pages into script deliveryIt comes out in your own voice
- Output encoding is context-specificThe plug has to match the socket
- Path traversal escapes the intended file areaTwo dots at a time
- Open redirects lend trusted domains to phishingYour livery, their destination
- Security headers shape browser behaviourInstructions the browser follows
