> NamedFile::open(Path::new("www/").join(file)).ok()
Is this vulnerable to the classic "../../../../../../../etc/passwd"?
Is this vulnerable to the classic "../../../../../../../etc/passwd"?
EDIT: I opened the documentation and found https://api.rocket.rs/rocket/request/trait.FromSegments.html I don't fully understand if the checking they do on '..' fixes the attack vector here.
ValidDir/../../../../../../../etc/passwdAnd on Japanese and Korean windows? It uses the yen symbol as path separator. Depending on how the path is read or interpreted, filtering the yen may be necessary.
https://msdn.microsoft.com/en-us/library/dd374047(v=vs.85).a...