Quote:
Originally Posted by Max Taxable
And since there was no way to read the source code, no real way to tell what all was in the file.
|
OK, but how is that a security hole (and what does it have to do with cookies)? Maybe if they are saying that someone was able to upload a php file as an image, then run it by putting it in an IMG tag? (No, that doesn't make sense, you could run it without the img tag).