<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Recent changes to bugs</title><link>https://sourceforge.net/p/file/bugs/</link><description>Recent changes to bugs</description><atom:link href="https://sourceforge.net/p/file/bugs/feed.rss" rel="self"/><language>en</language><lastBuildDate>Sun, 24 Apr 2005 20:59:01 -0000</lastBuildDate><atom:link href="https://sourceforge.net/p/file/bugs/feed.rss" rel="self" type="application/rss+xml"/><item><title>Security problem</title><link>https://sourceforge.net/p/file/bugs/2/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Hi!&lt;/p&gt;
&lt;p&gt;I found that if I change request string manualy I can&lt;br /&gt;
gain access to parent directory (relative to user's&lt;br /&gt;
home dir).&lt;/p&gt;
&lt;p&gt;For example:&lt;/p&gt;
&lt;p&gt;http:// my site&lt;br /&gt;
/fileadmin.php?op=home&amp;amp;folder=/home/user/www/site3/public_html/../../&lt;/p&gt;
&lt;p&gt;where /home/user/www/site3/public_html/ was user's home&lt;br /&gt;
dir.&lt;/p&gt;
&lt;p&gt;GLoom&lt;br /&gt;
gloom@gloo.ru&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Anonymous</dc:creator><pubDate>Sun, 24 Apr 2005 20:59:01 -0000</pubDate><guid>https://sourceforge.netae7d3f799323c801da6d9ba63fdd82f4105b475c</guid></item><item><title>Upload problem with large file sizes</title><link>https://sourceforge.net/p/file/bugs/1/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;When uploading a large file instead of returning the name &lt;br /&gt;
of the file to the script it will return 'none'. This results &lt;br /&gt;
in a failure to upload.&lt;/p&gt;&lt;/div&gt;</description><pubDate>Fri, 04 Jul 2003 17:31:47 -0000</pubDate><guid>https://sourceforge.net8729478829b38d7e3911cd55c02b41db6fb1f2b1</guid></item></channel></rss>