Quote:
Originally posted by Sharg
What's the security concern that attachement files folder storing involve that isn't involved by avatar folder storing ?
|
Avatars are always stored as xxxx.gif. Attachments can be of any file type that the administrator decides to allow. If an administrator decided to let .php files be uploaded, and they were stored as files on the system, anyone could run a php script that could destroy the server.
It's a bad idea.