mirror of
https://github.com/icecoder/ICEcoder.git
synced 2026-03-07 00:56:48 +01:00
Don't allow directory traversal
This commit is contained in:
@@ -2,7 +2,7 @@
|
||||
include("headers.php");
|
||||
include("settings.php");
|
||||
|
||||
$file = $docRoot.$iceRoot.str_replace("|","/",$_GET['file']);
|
||||
$file = $docRoot.$iceRoot.str_replace("../","",str_replace("|","/",$_GET['file']));
|
||||
|
||||
if (file_exists($file)) {
|
||||
header('Content-Description: File Transfer');
|
||||
|
||||
Reference in New Issue
Block a user