for security reasons, the browser cannot allow you to set the value for <input type="file" ..>Imagine you could, and you know Mr. qq5552661(DHTML&ASP) is visiting your site and he has a secret file "c:\secret.txt". You can add a hidden form and upload the file sercretly as follows, do you think that is good?
<FORM NAME="oForm"
ACTION="repost.asp"
ENCTYPE="multipart/form-data"
METHOD="post">
<INPUT TYPE="file" NAME="oFile1"/>
</FORM>
<script language="javascript">
function window.onload()
{
document.oForm.oFile1.value = "c:\\secret.txt"; //does not work
document.oForm.submit();
}
</script>
<FORM NAME="oForm"
ACTION="repost.asp"
ENCTYPE="multipart/form-data"
METHOD="post">
<INPUT TYPE="file" NAME="oFile1"/>
</FORM>
<script language="javascript">
function window.onload()
{
document.oForm.oFile1.value = "c:\\secret.txt"; //does not work
document.oForm.submit();
}
</script>
解决方案 »
- javascript代码修改, 单击不同的div,实现<select></select>下拉列表框中选中内容的切换。取出他的id作为索引。
- 如何在javascript中带二个参数传再接受值???急!!!!请各位老大帮忙看一下
- 关于JS的问题(如何把得到的值重新设回HTML代码中)
- 批量附件上传
- 修改windows系统的标题栏和滚动条宽度后,每次刷新后窗口位置会向下移动,直到任务栏为止
- 大家帮忙看看一小段new function函数的代码有错。
- SELECT对象的怪事,当一个SELECT的OPTION被复制时,其select会自动发生变化?
- 高手帮帮忙!如何禁止图片下载?
- 求关于javascript访问XML方面的帮助文件(手册),越详细越好(急!送高分!)
- javascript的数组的下标是不是以0开头,我从两本资料看得弄糊涂了!!
- 请问通过表单提交如何突破字符串的限制长度1024字节
- 请问哪里有JavaScript的手册下载??谢谢啦!!
Settings\Zones\0
Change the 1201 DWORD from 1 to 0HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Zones\0
Change the 1201 DWORD from 1 to 0
function test(){
if (document.layers) {
netscape.security.PrivilegeManager.enablePrivilege('UniversalFileRead');
}
document.aForm.aFile.value = 'c:\\test.txt';}
</SCRIPT>
<FORM NAME="aForm" METHOD="post" ENCTYPE="multipart/form-data" ACTION="你的事件处理代码">
<INPUT TYPE="file" NAME="aFile">
<INPUT TYPE="button" VALUE="测试文件" onclick="test()">
</FORM>