Merge pull request #14759 from aspangaro/10.0p45
FIX Yogosha report 4433 (backport)
This commit is contained in:
commit
f477613326
@ -222,7 +222,7 @@ if (! $accessallowed)
|
||||
if (preg_match('/\.\./', $fullpath_original_file) || preg_match('/[<>|]/', $fullpath_original_file))
|
||||
{
|
||||
dol_syslog("Refused to deliver file ".$fullpath_original_file);
|
||||
print "ErrorFileNameInvalid: ".$original_file;
|
||||
print "ErrorFileNameInvalid: ".dol_escape_htmltag($original_file);
|
||||
exit;
|
||||
}
|
||||
|
||||
|
||||
@ -232,7 +232,7 @@ if (! $accessallowed)
|
||||
if (preg_match('/\.\./', $fullpath_original_file) || preg_match('/[<>|]/', $fullpath_original_file))
|
||||
{
|
||||
dol_syslog("Refused to deliver file ".$fullpath_original_file);
|
||||
print "ErrorFileNameInvalid: ".$original_file;
|
||||
print "ErrorFileNameInvalid: ".dol_escape_htmltag($original_file);
|
||||
exit;
|
||||
}
|
||||
|
||||
|
||||
Loading…
Reference in New Issue
Block a user