Collected research
Cross-site File Upload Attacks
pdp shows that Flash defeats the assumption that file uploads cannot be forged cross-site. A compiled MXML application builds a URLRequest with a hand-written multipart/form-data body, including the filename sub-field HTML forms cannot express, and navigateToURL posts it to the victim's upload endpoint.
Record
- Researcher
- pdp
- Published by
- gnucitizen.org
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of pdp, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .