Details
Alert ID 100022
Alert Type Script Passive
Status alpha
Risk Informational
CWE 434
WASC 20
Technologies Targeted All
Tags CWE-434
More Info Scan Rule Help

Summary

The presence of a file upload form can lead to various security vulnerabilities, such as uploading malicious files or overwriting existing files, if proper validation and restrictions are not implemented. This can result in unauthorized code execution, data breaches, or denial of service attacks.

Solution

Implement strict validation and restrictions on uploaded files, including file type, size, and content. Use security measures like antivirus scanning and file storage outside the web root.

Other Info

References

Code

passive/Upload form discovery.js