This week's book giveaways are in the Refactoring and Agile forums.
We're giving away four copies each of Re-engineering Legacy Software and Docker in Action and have the authors on-line!
See this thread and this one for details.
Win a copy of Re-engineering Legacy Software this week in the Refactoring forum
or Docker in Action in the Cloud/Virtualization forum!
  • Post Reply
  • Bookmark Topic Watch Topic
  • New Topic

upload file - different browsers send different path name

 
Minh Nam
Ranch Hand
Posts: 57
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
Hi guys,

I use the following code to save a uploaded file on server:



If the file uploaded by Firefox, the fileName contains only file name.
If the file uploaded by IE, the fileName contains absolute path on client's computer which may exposes security threat.

So why's the different?
 
Bear Bibeault
Author and ninkuma
Marshal
Pie
Posts: 64631
86
IntelliJ IDE Java jQuery Mac Mac OS X
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
That is a security bug in IE.
 
Minh Nam
Ranch Hand
Posts: 57
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
Bear Bibeault wrote:That is a security bug in IE.

I tested with IE 6, maybe the later version fixes the bug.
 
Minh Nam
Ranch Hand
Posts: 57
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
I have to use this workaround:

 
  • Post Reply
  • Bookmark Topic Watch Topic
  • New Topic