Message103485
| Author |
gsakkis |
| Recipients |
brett.cannon, eric.araujo, gsakkis, hauser, mrts, rhettinger |
| Date |
2010年04月18日.12:05:35 |
| SpamBayes Score |
1.9286048e-05 |
| Marked as misclassified |
No |
| Message-id |
<1271592338.01.0.755764710475.issue2090@psf.upfronthosting.co.za> |
| In-reply-to |
| Content |
> On the surface this seems like a potential directory traversal attack
> hole, although I couldn't get past 'pkg' by passing '../../../', so I
> guess there must be other checks before attempting the import.
I rushed to post; it turns out one *can* access packages in parent directories, so I think it's accurate to describe it as a directory traversal hole. |
|