in reply to Re: CGI file uploads
in thread CGI file uploads
It's one thing to send some screwed up data (or maybe even some spam to a contact form) but to be able to actually send files to the server is something that doesn't really suprise me but I never thought about it.
Even if the form knows better than to accept unknown data, it's still sending all that extra file data to the server.
Guess there's really no way to prevent that though.
I was also thinking whether or not it was possible to pass a hidden form field AS a file upload field. Like download specific C:\ files on which the user doesn't know they are uploading.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^3: CGI file uploads
by polettix (Vicar) on Mar 13, 2006 at 18:07 UTC |