Reply to post: Re: That other guy is an idiot

jQuery? More like preyQuery: File upload tool can be exploited to hijack at-risk websites

Michael Wojcik Silver badge

Re: That other guy is an idiot

the fault isn't with jQuery itself, but with someone else's plugin for it that happens to rely on server-side code as well

Correct. jQuery is crap (though it's much-improved crap, compared to early versions), but in this case the fault is divided between Sebastian Tschan / Blueimp (jQuery File Upload author and maintainer) and Apache.

I'm inclined to give the lion's share to Apache - disabling .htaccess in the default configuration was really stupid - but Blueimp is not free of blame either. They should be following changes in their dependencies.

Also, frankly, I am not impressed with a file-upload widget that relies solely on .htaccess for security. (And their "fix" is to restrict the widget to image-file types by default; also not impressive.)

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon