[Tickets #7646] Re: Driver 'file' fails to open files with '..' anywhere in name

bugs at horde.org bugs at horde.org
Thu Nov 6 01:36:42 UTC 2008


DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/7646
------------------------------------------------------------------------------
  Ticket             | 7646
  Updated By         | Chuck Hagenbuch <chuck at horde.org>
  Summary            | Driver 'file' fails to open files with '..' anywhere
                     | in name
  Queue              | Gollem
  Version            | 1.0.3
  Type               | Bug
-State              | Unconfirmed
+State              | Feedback
  Priority           | 2. Medium
  Milestone          |
  Patch              | 1
  Owners             |
------------------------------------------------------------------------------


Chuck Hagenbuch <chuck at horde.org> (2008-11-05 20:36) wrote:

What about paths like file.pdf/../../../etc/passwd ?

Much less importantly, ereg_* is deprecated and against Horde CS;  
please use the pcre functions instead (although this particular case  
doesn't even need a regex).





More information about the bugs mailing list