I was wondering, isn't that unsafe ?
You allow every user to upload every file.
I know there are restrictions like extensions and permissions etc ... but if you just rename your file, you can easily upload every file.
I mean, if that file is a script of some kind, isn't there any possibility that uploads are unsafe ?
If the user can somehow execute a script on the server giving him root-powers ... I don't wanna be responsible for the consequences.
Am I totally paranoid or is it actually a bit unsafe ?
Thanks and come again
