Fix a security vulnerability for provisioning
This commit is contained in:
@@ -139,6 +139,10 @@ include "root.php";
|
|||||||
$mac = $this->mac;
|
$mac = $this->mac;
|
||||||
$file = $this->file;
|
$file = $this->file;
|
||||||
|
|
||||||
|
//remove ../ and slashes in the file name
|
||||||
|
$search = array('..', '/', '\\');
|
||||||
|
$file = str_replace($search, "", $file);
|
||||||
|
|
||||||
//get the domain_name
|
//get the domain_name
|
||||||
if (strlen($domain_name) == 0) {
|
if (strlen($domain_name) == 0) {
|
||||||
$sql = "SELECT domain_name FROM v_domains ";
|
$sql = "SELECT domain_name FROM v_domains ";
|
||||||
|
|||||||
Reference in New Issue
Block a user