in reply to Re: letting a browser client select a file to download by inode
in thread letting a browser client select a file to download by inode
More that passing out arbitrary files by inum could allow people to get access to files that they shouldn't (e.g. if your documents are served from the same filesystem as your Apache configuration someone could figure out the likely inum for httpd.conf; worse if your document root is on the same filesystem as /etc).
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^3: letting a browser client select a file to download by inode
by leocharre (Priest) on Dec 27, 2005 at 13:27 UTC |