#25 File names can overwrite other resources

Öppen
öppnade 5 år sedan av sindre · 0 kommentarer
sindre kommenterad 5 år sedan

When uploading a file it can overwrite other files, even those ondifferent levels due to lack of input validation. This is differentfrom uploading, as even without checking for file name, itshould be checked that it won’t overwrite another file.

When uploading a file it can overwrite other files, even those ondifferent levels due to lack of input validation. This is differentfrom uploading, as even without checking for file name, itshould be checked that it won’t overwrite another file.
sindre lade till denna till milstolpe Required fixes 5 år sedan
sindre added the
webpy
label 5 år sedan
sindre added the
bug
label 5 år sedan
sindre added the
security misconfiguration
label 5 år sedan
sindre modifierade milstolpen från Required fixes till Optional vulnerabilities 5 år sedan
Logga in för att delta i denna konversation.
Laddar…
Avbryt
Spara
Det finns inget innehåll än.