mirror of
https://github.com/pfsense/pfsense.git
synced 2025-10-26 11:38:35 +00:00
Strengthen path privilege check. Fixes #9513
* Removes/resolves any relative paths in the submitted URL
* Validates that the file exists
* Trims the path component off after in a nicer way
(cherry picked from commit 0604f68855)
This commit is contained in:
parent
2d7ec8bfdd
commit
ffe379adde
@ -30,6 +30,7 @@
|
||||
|
||||
function cmp_page_matches($page, & $matches, $fullwc = true) {
|
||||
|
||||
global $g;
|
||||
// $dbg_matches = implode(",", $matches);
|
||||
// log_error("debug: checking page {$page} match with {$dbg_matches}");
|
||||
|
||||
@ -37,11 +38,14 @@ function cmp_page_matches($page, & $matches, $fullwc = true) {
|
||||
return false;
|
||||
}
|
||||
|
||||
/* skip any leading fwdslash */
|
||||
$test = strpos($page, "/");
|
||||
if ($test !== false && $test == 0) {
|
||||
$page = substr($page, 1);
|
||||
list($file, $query) = explode('?', $page);
|
||||
$file = realpath( $g['www_path'] . '/' . ltrim($file, '/'));
|
||||
if (empty($file)) {
|
||||
/* File does not exist, or other path shenanigans */
|
||||
return false;
|
||||
}
|
||||
$page = str_replace($g['www_path'] . '/', '', $file);
|
||||
$page .= (!empty($query)) ? "?{$query}" : "";
|
||||
|
||||
/* look for a match */
|
||||
foreach ($matches as $match) {
|
||||
|
||||
Loading…
Reference in New Issue
Block a user