I solved some issues with Directory traversal
This commit is contained in:
@@ -91,6 +91,9 @@ function DumpHeaders ($filename)
|
||||
}
|
||||
|
||||
//$filename = PATH_UPLOAD . "$filename";
|
||||
G::LoadSystem('inputfilter');
|
||||
$filter = new InputFilter();
|
||||
$filename = $filter->xssFilterHard($filename, 'path');
|
||||
readfile( $filename );
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user