Skip to content

Commit

Permalink
Update 227-knowledge_base--File_upload_outside_document_root--.md
Browse files Browse the repository at this point in the history
  • Loading branch information
RiieCco committed Mar 12, 2019
1 parent 9820974 commit a43a08a
Showing 1 changed file with 1 addition and 1 deletion.
@@ -1,7 +1,7 @@
## Description:

Files that are uploaded by users or other untrusted services should always be placed outside
of the document root. This is to prevent malicious files from being parsed by attackers such as PHP files.
of the document root. This is to prevent malicious files from being parsed by attackers such as PHP/HTML/Javascript files.

Should an attacker succeed to bypass file upload restrictions and upload a malicous file, it would
be impossible for the attacker to parse these files since they are not located inside of the
Expand Down

0 comments on commit a43a08a

Please sign in to comment.