3 ms·
It's related to the intentions this guy had in his head. If someone would find this vulnerability in Updrop after plenty of files were uploaded and the service
by plugnburn 11y ago
It's related to the intentions this guy had in his head.
If someone would find this vulnerability in Updrop after plenty of files were uploaded and the service became popular, compromising the security with any evil intention would bring a disaster. Now that PHP file uploading is already closed both at the client and server sides, it became relatively safe to operate.
Although, until filename(1), (2) etc issue is fixed, this service isn't worth any serious consideration anyway. Too many newbie mistakes here.
Update: this seems to be fixed too for now (not a perfect variant, as the original name is lost forever, but a plausible solution that's much better than it was). Nice!
- devbob 11y agoHey, I appreciate your vigilance, thanks