Of course, anyone using WordPress, Drupal, or any other PHP-based website engine can't disable PHP. I think a majority of the websites currently running fall under that case.
I think the best solution, where the site owner has the necessary control, is to put the upload directory outside the document root. That's more idiot-proof than the alternatives.
no subject
Date: 2018-10-23 09:36 pm (UTC)I think the best solution, where the site owner has the necessary control, is to put the upload directory outside the document root. That's more idiot-proof than the alternatives.