Hacker News new | ask | show | jobs
by TarqDirtyToMe 3391 days ago
I'd be interested to see if any web-based control panels are vulnerable in a similar way. All of the client_*_temp_path directives are valid in http,server, and location contexts so you have a lot of flexibility there.