veracode medium issues
Directory Transversal, OS Command Injection
This commit is contained in:
@@ -3797,6 +3797,10 @@ class Cases
|
||||
if (!is_dir($strPathName)) {
|
||||
G::verifyPath($strPathName, true);
|
||||
}
|
||||
|
||||
G::LoadSystem('inputfilter');
|
||||
$filter = new InputFilter();
|
||||
$file = $filter->xssFilterHard($file, 'path');
|
||||
|
||||
copy($file, $strPathName . $strFileName);
|
||||
chmod($strPathName . $strFileName, 0666);
|
||||
|
||||
Reference in New Issue
Block a user