Details
-
Bug
-
Resolution: Timed out
-
Medium
-
None
-
5.8-m26
-
1
-
Severity 2 - Major
-
2
-
Description
Upload or rename an existing attachment with a name like "\.png" or "';alert(666)//\';alert(666)//";alert(666)//\";alert(666)//--></SCRIPT>">'><SCRIPT>alert(666)</SCRIPT>
'"><script>alert(666)</script>.png"
The attachment will not download (<base url>/download/attachments/<page id>/%5C.png will return 400) so it won't display or work on any macro, etc