image crud - XSS vulnerability
- Single Page
Posted 22 January 2013 - 21:51 PM
I don't know the last version of image crud but with the actual you can upload anything (.php, .exe).
And the Class ImageUploadHandler doesn't work :
You can write whatewer you want in the 'accept_file_types', you can still upload .exe or .php files.
Posted 26 January 2013 - 18:43 PM
Posted 27 January 2013 - 19:38 PM