use nodev,nosuid together with nfsextras if you do not trust server...
Attach a file by drag & drop or click to upload