Opened 14 years ago

Closed 14 years ago

#401 closed defect (fixed)

Do not allow use of ".." in file upload/download service

Reported by: fxp Owned by: geonetwork-devel@…
Priority: major Milestone: v2.7.0
Component: General Version: v2.6.1
Keywords: Cc:

Description

Fname parameter could contains ".." which is not safe in some configuration.

Fixed in :

Attachments (1)

401.patch (6.5 KB ) - added by fxp 14 years ago.

Download all attachments as: .zip

Change History (2)

by fxp, 14 years ago

Attachment: 401.patch added

comment:1 by fxp, 14 years ago

Resolution: fixed
Status: newclosed
Note: See TracTickets for help on using tickets.