Extra traversal check.

git-svn-id: http://svn.automattic.com/wordpress/branches/2.3@6521 1a063a9b-81f0-0310-95a4-ce76da25c4cd
This commit is contained in:
ryan 2007-12-29 03:14:53 +00:00
parent de80358206
commit f7ce06a547
1 changed files with 3 additions and 0 deletions

View File

@ -43,6 +43,9 @@ function get_real_file_to_edit( $file ) {
}
function validate_file( $file, $allowed_files = '' ) {
if ( false !== strpos( $file, '..' ))
return 1;
if ( false !== strpos( $file, './' ))
return 1;