Skip to content

Commit

Permalink
Resolve #1390 encode file names (#2069)
Browse files Browse the repository at this point in the history
  • Loading branch information
elarlang authored Sep 11, 2024
1 parent aa7b191 commit 8f05992
Showing 1 changed file with 1 addition and 0 deletions.
1 change: 1 addition & 0 deletions 5.0/en/0x20-V12-Files-Resources.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,6 +51,7 @@ Although zip bombs can be effectively tested using penetration testing technique
| **12.5.1** | [MOVED TO 14.3.6] | | | | |
| **12.5.2** | [MOVED TO 50.5.1] | | | | |
| **12.5.3** | [MODIFIED, MOVED FROM 12.3.4] Verify that the application validates or ignores user-submitted filenames, including in a JSON, JSONP, or URL parameter and specifies a filename in the Content-Disposition header in the response. |||| 641 |
| **12.5.4** | [ADDED] Verify that file names served (e.g., in HTTP response headers or email attachments) are encoded or sanitized (e.g., following RFC 6266) to preserve document structure and prevent injection attacks. |||| |

## V12.6 SSRF Protection

Expand Down

0 comments on commit 8f05992

Please sign in to comment.