Opened 12 years ago

Closed 11 years ago

#78 closed Bug (fixed)

ASP.Net connector still accepts the user files path from the URL

Reported by: Frederico Caldeira Knabben Owned by: Frederico Caldeira Knabben
Priority: Must have (possibly next milestone) Milestone: FCKeditor.Net 2.5
Component: Server : ASP.Net Version:
Keywords: Cc:

Description

The "ServerPath" URL parameter can still be used to set the server path for the user files folder.

We have been pressed to leave this option in the past, but this is a huge security risk. So, let's remove it. Those users who still prefer the URL will have to accept this option and understand that this is a important security limit.

Change History (3)

comment:1 Changed 12 years ago by Frederico Caldeira Knabben

Milestone: FCKeditor 2.5FCKeditor.Net 2.3

comment:2 Changed 11 years ago by Frederico Caldeira Knabben

Fixed with [1168].

comment:3 Changed 11 years ago by Frederico Caldeira Knabben

Resolution: fixed
Status: newclosed
Note: See TracTickets for help on using tickets.
© 2003 – 2019 CKSource – Frederico Knabben. All rights reserved. | Terms of use | Privacy policy