r3 - 13 Feb 2006 - 12:39:17 - CrawfordCurrieYou are here: TWiki >  Codev Web > ViewfileDoesntCheckPermissions
Tags:
, create new tag

Bug: viewfile does not check permissions

AFAICT the shipped viewfile script does not check permissions. This means that a footpad who knew the name of an attachment to a secured topic can access it. Worse, if the filename parameter is not passed, the footpad can get a listing of the pub directory for that topic.

-- CrawfordCurrie - 03 Dec 2004

Fixed in Dakar.

 
Edit | WYSIWYG | Attach | Printable | Raw View | Backlinks: Web, All Webs | History: r3 < r2 < r1 | More topic actions
 
Powered by TWiki
This site is powered by the TWiki collaboration platformCopyright © by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback SourceForge.net Logo