[TYPO3-core] RFC: allow .. in names -> check for ../ (#3364)
Martin Kutschker
Martin.Kutschker at blackbox.net
Fri Apr 28 21:24:32 CEST 2006
Hi!
Branches: HEAD / TYPO3_4-0
Problem:
It seems that t3lib_div::validPathStr() is to eager in denying paths. While it's possible to add a file with two dots in it, deleting (probably among other things) fails.
Solution:
Check for ../ instead of ..
Masi
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: text/x-diff
Size: 722 bytes
Desc: not available
Url : http://lists.netfielders.de/pipermail/typo3-team-core/attachments/20060428/afd099ef/attachment.bin
More information about the TYPO3-team-core
mailing list