My free webhosting script needs 2 security flaws fixed. The script allows users to upload/edit/rename/save files in there directory (which is good), and elsewhere (which is bad).
Basically, using "../" any member can upload/rename/save/edit any file on www, perhaps even to other member directories, though they should only be able to work on files in there member directory.
I can provide winning bidder the script, or ftp access where they can fix it, as its already installed on a domain. This is my script, I do own all copyrights to it. I would prefer the fixes be made on the site, as opposed to me sending you the script.
1) Complete and fully-functional working program(s) in executable form as well as complete source code of all work done.
2) Deliverables must be in ready-to-run condition, as follows (depending on the nature of the deliverables):
a) For web sites or other server-side deliverables intended to only ever exist in one place in the Buyer's environment--Deliverables must be installed by the Seller in ready-to-run condition in the Buyer's environment.
b) For all others including desktop software or software the buyer intends to distribute: A software installation package that will install the software in ready-to-run condition on the platform(s) specified in this bid request.
3) All deliverables will be considered "work made for hire" under U.S. Copyright law. Buyer will receive exclusive and complete copyrights to all work purchased. (No GPL, GNU, 3rd party components, etc. unless all copyright ramifications are explained AND AGREED TO by the buyer on the site per the coder's Seller Legal Agreement).