Bugtraq mailing list archives
Re: Uber Uploader <= 5.3.6 Remote File Upload Vulnerability
From: recklessb () users sourceforge net
Date: 18 Dec 2007 20:31:13 -0000
UU already provides a mechanism to detect file extensions client and server side. It is "YOUR" responsibility when you install this script to add file extensions that you may or may not want uploaded. Jeesh! $disallow_extensions = '/(sh|php|php3|php4|php5|py|shtml|phtml|cgi|pl|plx|htaccess|htpasswd)$/i'; $allow_extensions = '/(jpg|jpeg|gif|bmp)$/i';
Current thread:
- Uber Uploader <= 5.3.6 Remote File Upload Vulnerability sys-project (Dec 17)
- <Possible follow-ups>
- Re: Uber Uploader <= 5.3.6 Remote File Upload Vulnerability recklessb (Dec 18)
