Yes, PHP uploads the files in the /tmp dir and gives them a unique filename. As that point they are read write by the webserver, but are not executable so your safe. Fortunatly, UNIX systems have feew virii and trojans out. Your safe :) Regards,
Chris Murley
Systems Administrator\Programmer