Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Security issue with "Files" admin module
#7
bugman Wrote:If any product with typical installation out-of-box allow either admin or ordial user to acces files/directotires they're not granted - it's a security hole for me.
I hear what you say and I agree with your logic.

I just tried adding more levels of ../ to the URL and I can get back to the filesystem root to view directory contents (I can't do anything to them as the server permissions prevent that). This is not on a properly hardened commercial production server, so it may not be a true indication.

So, I would like to change my view and say that it certainly needs to be addressed.
--
Nick.
Reply


Messages In This Thread
Security issue with "Files" admin module - by hameau - 2011-05-19, 19:08:34



Users browsing this thread: 4 Guest(s)