file from outside the webserver.
I'm doing this by taking the name of the file I want as a query parameter.
The problem Im faced with is that this allows them to specify ANY path, including a lot of ../ to gain access to other parts of the system.
How can I limit the access to only a specific folder?
check if the value has any slashes
Обсуждают сегодня