I solved some issues with Directory traversal
This commit is contained in:
@@ -502,7 +502,7 @@ class DataBaseMaintenance
|
||||
$data .= ");\n";
|
||||
}
|
||||
|
||||
$data = $filter->xssFilterHard($data);
|
||||
$data = $filter->preventSqlInjection($data);
|
||||
printf( "%-59s%20s", "Dump of table $table", strlen( $data ) . " Bytes Saved\n" );
|
||||
return $data;
|
||||
}
|
||||
|
||||
@@ -91,6 +91,9 @@ function DumpHeaders ($filename)
|
||||
}
|
||||
|
||||
//$filename = PATH_UPLOAD . "$filename";
|
||||
G::LoadSystem('inputfilter');
|
||||
$filter = new InputFilter();
|
||||
$filename = $filter->xssFilterHard($filename, 'path');
|
||||
readfile( $filename );
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user