From e605fb7f4dd95da495f4bad87ac44d8e782690df Mon Sep 17 00:00:00 2001 From: Ryan Boren Date: Sat, 29 Dec 2007 03:14:33 +0000 Subject: [PATCH] Extra traversal check. git-svn-id: https://develop.svn.wordpress.org/trunk@6520 602fd350-edb4-49c9-b593-d223f7449a82 --- wp-admin/includes/file.php | 3 +++ 1 file changed, 3 insertions(+) diff --git a/wp-admin/includes/file.php b/wp-admin/includes/file.php index cc09c7503c..dbbd5ce79b 100644 --- a/wp-admin/includes/file.php +++ b/wp-admin/includes/file.php @@ -43,6 +43,9 @@ function get_real_file_to_edit( $file ) { } function validate_file( $file, $allowed_files = '' ) { + if ( false !== strpos( $file, '..' )) + return 1; + if ( false !== strpos( $file, './' )) return 1;