Hacker News new | ask | show | jobs
by NewsReader42 4285 days ago
You should also check the size of the image to make sure it's actually an image. I can quite easily get a php file into your system using your current way as you ONLY check for extension.
1 comments

By size I mean dimensions.