agentzh / lua-resty-multipart-parser

Simple multipart data parser for OpenResty/Lua
39 stars 18 forks source link

The function of getting filename can be bypassed #3

Open JoyChou93 opened 7 years ago

JoyChou93 commented 7 years ago
Content-Disposition: form-data;filename="x.jpg";name="file";filename="xx.php"

returns x.jpg

But, in fact, uploaded file name is xx.php.

The regex of get filename is risky.