If you have a file upload form then you'll want to address all data files with terrific suspicion. If you are making it possible for users to upload photos, you cannot count on the file extension or the mime type to validate that the file is an image as these http://0109730618244318.ampblogs.com/toto-site-An-Overview-31788996