Security Leak on Uploads? [message #32115] |
Fri, 09 June 2006 11:57 |
Ryo2023
Messages: 8 Registered: May 2006
Karma: 0
|
Junior Member |
|
|
It might be too obvious, and too easy.
But it seems to be an Issue.
I tested my Forum and was quite shocked.
When i edit any HTML-File (including Scripting) then rename like test.jpg and upload it as an attachment in the Message-Editor, the Message will be accepted and posted to the forum.
Now if i use IE and click on that link, which shows "test.jpg" the File will be opened and executed !
I tried this with a normal user account.
Now i think it might be a good idea to stop an file being executed. Even plain HTML might be a phishing risk.
I configured all Forums to zero - upload limit.
[Updated on: Fri, 09 June 2006 12:02] Report message to a moderator
|
|
|
|
Re: Security Leak on Uploads? [message #32120 is a reply to message #32118] |
Fri, 09 June 2006 14:37 |
Ilia
Messages: 13241 Registered: January 2002
Karma: 0
|
Senior Member Administrator Core Developer |
|
|
This is a bug in Internet Explorer, that causes it to parse images with invalid mime type as HTML. A fix for this bug was already applied to CVS and will be a part of the next FUDforum release.
FUDforum Core Developer
|
|
|
|