From: Ray B. I. <rb...@cl...> - 2001-07-12 13:22:00
|
> For the sake of completeness, if you did that, you'd have to exclude the > following attempts as well: > > "../../../../../../etc/passwd" > "./../../../../../etc/passwd" Well, for complete completeness, you should use the string checks that are in cvs already, which Lewis mentioned on the main list. They need to check for any occurrence of '../' or the first character being '/', and if either of those are the case, they need to just ignore the 'mailbox' settings and use the Inbox. -r3- |