Skip to content
This repository was archived by the owner on Oct 14, 2024. It is now read-only.
This repository was archived by the owner on Oct 14, 2024. It is now read-only.

Improve AjaxFileUpload security #336

@MikhailTymchukDX

Description

@MikhailTymchukDX

AjaxFileUpload is exposed to several attacks:
 

  • Uploading a file with an arbitrary extension
  • A DoS attack on the server where this control is located
  • It is possible to obtain info about files outside the temporary upload folder

 
Consider improving extender security.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions