|
ouch those are both terrible exploits hah
although kinda limited because in order for it to work you must get the person to somehow type the path and filename of the file you want uploaded, using their little example the word boot.ini is taken from the text you write in the box
kinda funny though , texasdreams could get us all if he said " repeat after me without quoting me " etc etc then tied it into the webform..
basically they float the hidden file upload box in the text field
__________________
hatisblack at yahoo.com
|