Share

XTemplate

Tracker: Patches

5 Solve mod_ruby security error - ID: 1073184
Last Update: Attachment added ( nobody )

mod_ruby security level (1) does not allow to open file
via the 'import' action.
If you untaint filename before using it, it works.


Nobody/Anonymous ( nobody ) - 2004-11-25 14:05

5

Open

None

Nobody/Anonymous

xtemplate

None

Public


Comments




Log in to comment.

No follow-up comments have been posted.

Attached File ( 1 )

Filename Description Download
xpath.rb.patch Patch - untaint file name in 'import' Download

Change ( 1 )

Field Old Value Date By
File Added 110078: xpath.rb.patch 2004-11-25 14:05 nobody