Bug 11661: sanitize file names supplied to edithelp.pl
authorChris Cormack <chris@bigballofwax.co.nz>
Sat, 1 Feb 2014 02:06:58 +0000 (15:06 +1300)
committerGalen Charlton <gmc@esilibrary.com>
Wed, 5 Feb 2014 01:36:10 +0000 (01:36 +0000)
commit7baf02c263a627b1454577b3141a0af4b8f963d1
tree8bb38b10dcd78a98fb43d4c0a36f8e8e1d048bda
parentd1b6e0646fd6a70f6724189554e80aaa68aec64b
Bug 11661: sanitize file names supplied to edithelp.pl

This patch corrects an issue whereby edithelp.pl could
be used to create or modify arbitrary files on the server
with the permissions of the Apache user.

Signed-off-by: Galen Charlton <gmc@esilibrary.com>
Signed-off-by: Jonathan Druart <jonathan.druart@biblibre.com>
Signed-off-by: Galen Charlton <gmc@esilibrary.com>
edithelp.pl