还是觉得image-clipboard插件比较好用,暂时稍微进行了下修改来规避上传漏洞
$file_ext = array("jpg", "gif", "bmp", "jpeg","png","tif","ico");
$ext = strtolower($ext);
if (in_array($ext, $file_ext)) {
$ext =$ext;
}
else{
$ext = "jpg";
}
10.09: 对插件目录进行重命名,对上传文件进行随机md5