File upload security is more than extension checking

Checking the extension establishes almost nothing, because the name is chosen by whoever uploads it.

What matters is what the server does with the file: where it is stored, whether that location can execute anything, what the content actually is, and whether it is served back with a type that makes the browser run it. Most upload flaws are about handling rather than about the check at the door.

More on Web application security