Uploaded image for project: 'ZK'
  1. ZK
  2. ZK-1742

How does org.zkoss.zkmax.au.http.AuDownloader ensure that an attacker can't use it to access an arbitrary file on the server?

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Minor Minor
    • None
    • 6.5.2
    • ZK Update Engine
    • None
    • production

      AuDownloader uses new File(path) and new URL(path) but it's unclear whether the paths are sanitized somewhere to prevent a remote attacker from accessing any resource on the server (or even attacking different servers by using a global URL)

            Unassigned Unassigned
            stevegreensill stevegreensill
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated: