> The main problem is having effectively web-accessible content in the
> web root. It's virtually a flat-out "don't ever do it".

I agree. But there have been parent path escaping issues in the past
that allow attackers to reference files outside of the web root even.

A bit more clarity around this part of the exploit would be more helpful.

Reply via email to