# \[PHP\] Secure upload script?

**URL:** <https://forum.kirupa.com/t/php-secure-upload-script/180770>\
**Category:** programming\
**Created:** [March 3, 2006, 8:11am UTC](https://forum.kirupa.com/t/php-secure-upload-script/180770 "2006-03-03T08:11:34Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![pete\_zahut](https://avatars.discourse-cdn.com/v4/letter/p/91b2a8/32.png) [@pete\_zahut](https://forum.kirupa.com/u/pete_zahut)\
**Post date:** [March 3, 2006, 8:11am UTC](https://forum.kirupa.com/t/php-secure-upload-script/180770/1 "2006-03-03T08:11:34Z")

</div>

Hi,

In another thread we were discussing if the following code is secure for uploading files. But there wasn’t much response so I put it here! :stunned:

```php
<?PHP
    $target_path = "uploads/";
    $target_path = $target_path . basename( $_FILES['Filedata']['name']);

    if(move_uploaded_file($_FILES['Filedata']['tmp_name'], $target_path))
    {
         echo "The file ". basename( $_FILES['Filedata']['name']). " has been uploaded";
    }
    else
    {
         echo "There was an error uploading the file, please try again!";
    }
    ?> 

```

It is called in the AS like so:

[AS]listener.onSelect = function(selectedFile:FileReference):Void {  
statusArea.text = "Attempting to upload " + selectedFile.name;  
selectedFile.upload(“uploadFile.php”);  
};[/AS]

So can other people abuse you(r script/server)?  
Can you limit it in file size?  
Can you specify dimensions for the image? (It only uploads images for me)  
…?

:} Pete!
