2017-02-13 UTC
# petermolnar I would add an extra fix: limit the mime type only, but have a fix list of extension according to the mime type (reverse mime magic table). The reason why it was executed is because it was called .php, and the php servers are usually configured to pick .php files up. If it was named at the original location x.php, but you renamed it according to the mime type as x.jpg, this would not have happened.