Re: [Full-disclosure] file upload widgets in IE and Firefox have issues

2006-06-12 Thread Charles McAuley
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Danny wrote: Hi , I read your article , but since I am not at all at home when scripting comes up,I still am wondering what this issue is exactly. My web-foo is not that strong either. Bart van Arnhem made a much better example in IE than I

[Full-disclosure] file upload widgets in IE and Firefox have issues

2006-06-05 Thread Charles McAuley
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hey all, aside from the new file upload vulnerability in Firefox 1.5.0.3 and below, I discovered two others a year ago (one in IE, the other in Firefox) in the same component. I'm a little obsessed with the file input widget. Since then i've