Reply to post:

jQuery? More like preyQuery: File upload tool can be exploited to hijack at-risk websites

mosw

From what I see in the Apache 2.4 documentation (not sure about 2.3.9) support for .htaccess files is determined by the directives applied. So the story is really about bad server configuration rather than any specific problems with jQuery file upload plugin. Clearly the plugin documentation should emphasize that .htaccess support is required.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon