Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Security issue with "Files" admin module
#5
I disagree with you guys. If any product with typical installation out-of-box allow either admin or ordial user to acces files/directotires they're not granted - it's a security hole for me. If File module was primary goal to reach the upload's (and it's children) folder - then no other (parent) folder should be accessed. I think of it like a chroot in linux.
Reply


Messages In This Thread
Security issue with "Files" admin module - by bugman - 2011-05-19, 18:26:45



Users browsing this thread: 2 Guest(s)