Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's one possibility. Another common flaw is upload/download features, where you can get directory traversal (../) in the upload or download file name that you are specifying.

When you've got file read, procfs is very nice :)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: