Menu

#11 Security Bug?

open
nobody
None
5
2002-09-18
2002-09-18
No

In the new open/save Dialogs it is possible to select .htm
and .html files.
But it is possible the read/save files with any file
extensions if the HTTP-POST-Parameter are
manipulated.

This is not a real security bug, but the UI should allow
the same as you can do with a little knowledge of HTTP-
Post.

Discussion


Log in to post a comment.