Skip to content

Latest commit

 

History

History
13 lines (7 loc) · 551 Bytes

vulnerable-code-5.md

File metadata and controls

13 lines (7 loc) · 551 Bytes

SecurityExplained S-17: Vulnerable Code Snippet - 5

Vulnerable Code:

Vulnerable Code

Solution:

The issue in this code snippet is that the files are stored without any extension. The Apache does not attach a Content-Type header in the response. Modern browsers will interpret these files as HTML which may lead to an attack such as Stored Cross-Site Scripting.

Code Credits: SonarSource

Follow Twitter Thread