-
Notifications
You must be signed in to change notification settings - Fork 739
Closed
Labels
securityExploits, attacks, dangerous leaks.Exploits, attacks, dangerous leaks.
Description
On one of my servers, if you were to go to:
mydomain.com/laravel-filemanager/download?working_dir=&type=Files&file=../../../../../../../../../../../../../../../homepages/45/d641872465/htdocs/.bash_history
It'll actually download the file, this is problematic because you can essentially break out of the application and affect the actual server.
I need to look into how I could secure this but I thought I'd bring it to your attention.
lanhhuyet510
Metadata
Metadata
Assignees
Labels
securityExploits, attacks, dangerous leaks.Exploits, attacks, dangerous leaks.