This week's book giveaway is in the Java 8 forum.
We're giving away four copies of Java 8 in Action and have Raoul-Gabriel Urma, Mario Fusco, and Alan Mycroft on-line!
See this thread for details.
The moose likes Servlets and the fly likes upload file - different browsers send different path name Big Moose Saloon
  Search | Java FAQ | Recent Topics | Flagged Topics | Hot Topics | Zero Replies
Register / Login


Win a copy of Java 8 in Action this week in the Java 8 forum!
JavaRanch » Java Forums » Java » Servlets
Bookmark "upload file - different browsers send different path name" Watch "upload file - different browsers send different path name" New topic
Author

upload file - different browsers send different path name

Minh Nam
Ranch Hand

Joined: Sep 10, 2011
Posts: 57
Hi guys,

I use the following code to save a uploaded file on server:



If the file uploaded by Firefox, the fileName contains only file name.
If the file uploaded by IE, the fileName contains absolute path on client's computer which may exposes security threat.

So why's the different?


Advanced java topics
Bear Bibeault
Author and ninkuma
Marshal

Joined: Jan 10, 2002
Posts: 60077
    
  65

That is a security bug in IE.


[Asking smart questions] [Bear's FrontMan] [About Bear] [Books by Bear]
Minh Nam
Ranch Hand

Joined: Sep 10, 2011
Posts: 57
Bear Bibeault wrote:That is a security bug in IE.

I tested with IE 6, maybe the later version fixes the bug.
Minh Nam
Ranch Hand

Joined: Sep 10, 2011
Posts: 57
I have to use this workaround:

 
I agree. Here's the link: http://aspose.com/file-tools
 
subject: upload file - different browsers send different path name
 
Similar Threads
Store file in access
how to upload file
upload file question
Submit multipart and form data
How do I get request parameters when the form is encoded?