2011-05-19, 18:26:45
I disagree with you guys. If any product with typical installation out-of-box allow either admin or ordial user to acces files/directotires they're not granted - it's a security hole for me. If File module was primary goal to reach the upload's (and it's children) folder - then no other (parent) folder should be accessed. I think of it like a chroot in linux.