-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Raymond Camden wrote:
| Are you sure that's possible? This would seem like a (minor) security
| risk to me.

not really.... you can't write to the file upload field and lets face
it, if you put something in there by browsing and selecting a file, your
going to most likely send it up to the server anyway and i think cross
frame and domain security blocks non-local js from reading the values too

it's really a neat trick actually, nice user feedback for image file upload

z
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6-2 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAj0STK0ACgkQm98oI6K7h0h2pgCcCAfkVXSGGjDuS9m+O/rQo82F
T1AAoLZM8J3n/4eYMB9v8FM7nfC1vXge
=5Vn0
-----END PGP SIGNATURE-----

______________________________________________________________________
Your ad could be here. Monies from ads go to support these lists and provide more 
resources for the community. http://www.fusionauthority.com/ads.cfm
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/[email protected]/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists

Reply via email to