Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Security issue with "Files" admin module
#1
I've found, that user can access files and folder outside default "uploads" folder by just adding "../" to url like that:
Quote:http://sitename.com/admin/upload.php?path=../
This is kind of security hole for VDS hosting, when one has multiple websites owned by only user (usually [apache:apache] or [httpd:httpd]) and relies on application's logic handling web user permissions.
Reply


Messages In This Thread
Security issue with "Files" admin module - by bugman - 2011-05-19, 17:19:43



Users browsing this thread: 3 Guest(s)