quote:Originally posted by Menthix
Removed the FileServer script from the site until this is fixed. I know it was reported over half a year ago, just didn't read the thread. Thanks to John for pointing me to it.
Will inform the creator too, but since his last post was in 2006 and all I have to contact is his forum profile I doubt it will result in much.
<from first page>
* v1.1.1
* Huge Security Fix (!cd ..\..\..\etc allowed to browse the whole disk)
I'm using version 1.1.2 and it does not have the bug as mentioned above...
Posts: 5537 Reputation: 102
40 / /
Joined: Mar 2002
RE: [Release] FileServer Script v1.1.2
quote:Originally posted by Phazeus
* v1.1.1
* Huge Security Fix (!cd ..\..\..\etc allowed to browse the whole disk)
I'm using version 1.1.2 and it does not have the bug as mentioned above
Hmm, good point.
Where did you download 1.1.2 (or even 1.1.1) though? The startpost only links to the download database, which was still hosting 1.0 at the time I removed it. As far as I know Pai never submitted any update to the download database.
This post was edited on 02-11-2010 at 02:36 PM by Menthix.