Author Topic: Upload without permission  (Read 2524 times)

0 Members and 1 Guest are viewing this topic.

rootarded

  • Guest
Upload without permission
« on: October 29, 2006, 01:47:57 AM »
Hello.

I just downloaded this piece of software and found out that it's possible to upload to folder which you do not have permission to upload to by simply creating your own html form, add the files and change the action parameter in the form to the folder you want to upload to.

This should be fixed ASAP.

Offline ~GeeS~

  • Tireless poster
  • ****
  • Posts: 270
  • "The web was made for sharing..."
    • View Profile
Re: Upload without permission
« Reply #1 on: October 29, 2006, 12:09:48 PM »
 ???
In order to reproduce what you've found, could you please describe exactly what you've done with your HTML and how you've  protected the upload folder?
~GeeS~

Offline rejetto

  • Administrator
  • Tireless poster
  • *****
  • Posts: 13146
    • View Profile
Re: Upload without permission
« Reply #2 on: October 29, 2006, 05:40:54 PM »
yes, fixed.
i'm now fixing other bugs, and will publish a new build in few hours.

Offline rejetto

  • Administrator
  • Tireless poster
  • *****
  • Posts: 13146
    • View Profile
Re: Upload without permission
« Reply #3 on: October 29, 2006, 07:55:45 PM »
please update to version 2.1a