[fixed] filemanager directory traversal

The members of the Dev team will place issues here that they consider to be solved.
Post Reply
dwave
Forum Members
Forum Members
Posts: 39
Joined: Mon Aug 13, 2007 11:15 am
Location: Israel

[fixed] filemanager directory traversal

Post by dwave »

The filemanager allows directory traversals and therefore everybody with the permissions to modify files can upload files outside the upload-directory.

Steps to reproduce:
1. (optional) Create User with permission to modify files but without permission for the "Advanced usage of the the File Manager module".
2. Go to the filemanager, upload files
3. Manipulate the hidden field <input id="m1_path" name="m1_path"> to contain for example the path /uploads/../../
4. Upload a file
User avatar
Rolf
Power Poster
Power Poster
Posts: 7825
Joined: Wed Apr 23, 2008 7:53 am
Location: The Netherlands
Contact:

Re: filemanager directory traversal

Post by Rolf »

I can't repoduce on SVN rev. 7361

But I can't change folders in FM anymore.
Perhaps the result of fixing this issue??

Rolf
- + - + - + - + - + - + -
LATEST TUTORIAL AT CMS CAN BE SIMPLE:
Migrating Company Directory module to LISE
- + - + - + - + - + - + -
Image
User avatar
Rolf
Power Poster
Power Poster
Posts: 7825
Joined: Wed Apr 23, 2008 7:53 am
Location: The Netherlands
Contact:

Re: filemanager directory traversal

Post by Rolf »

Should be fixed in SVN rev. 7361
- + - + - + - + - + - + -
LATEST TUTORIAL AT CMS CAN BE SIMPLE:
Migrating Company Directory module to LISE
- + - + - + - + - + - + -
Image
Post Reply

Return to “Closed Issues”