rhushikeshc / clients-oriented-ftp

Automatically exported from code.google.com/p/clients-oriented-ftp
0 stars 0 forks source link

Security issue - full path disclosure #255

Open GoogleCodeExporter opened 8 years ago

GoogleCodeExporter commented 8 years ago
What steps will reproduce the problem?
1. Log in as a client.
2. Grab path to the thumbnail of logo.
3. Set width ($_GET["w"]) parameter to -1.

What is the expected output? What do you see instead?
a. Error or image scaled by default dimensions. 
b. That: http://i.imgur.com/SFPDSSY.png

What version of the product are you using? On what operating system?
version r375 

Please provide any additional information below.
caching thumbnail would be cool 8)

Original issue reported on code.google.com by adamos...@gmail.com on 13 Apr 2013 at 2:32