commons-user mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Hassan Schroeder <hassan.schroe...@gmail.com>
Subject Re: [fileupload] - Question about uploading additional files other than the ones in the form?
Date Sat, 06 Sep 2014 19:57:04 GMT
On Sat, Sep 6, 2014 at 12:29 PM, Konrad Zuse <thekonradzuse@hotmail.com> wrote:

> So again, user selects file, I read file, then select other files from their system that
are needed for the first file, and upload them all up at the same time.

So "other files" like, say "/etc/passwd"?  :-)

Short answer: No, you can't do this, at least with a standard browser
sending form data.

If you write your own upload client and convince people to install and
use it you can allow all kinds of insanely insecure operations.

HTH,
-- 
Hassan Schroeder ------------------------ hassan.schroeder@gmail.com
http://about.me/hassanschroeder
twitter: @hassan

---------------------------------------------------------------------
To unsubscribe, e-mail: user-unsubscribe@commons.apache.org
For additional commands, e-mail: user-help@commons.apache.org


Mime
View raw message