From 9a8139f5713a12700a04e3bc3b335e9b46b6d6ba Mon Sep 17 00:00:00 2001 From: Silvan Calarco Date: Mon, 2 Aug 2021 09:55:39 +0200 Subject: [PATCH] cgi-bin/text-to-html-filter.cgi: security check on path prefix --- cgi-bin/text-to-html-filter.cgi | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cgi-bin/text-to-html-filter.cgi b/cgi-bin/text-to-html-filter.cgi index 44f43e5..ce7f7ba 100755 --- a/cgi-bin/text-to-html-filter.cgi +++ b/cgi-bin/text-to-html-filter.cgi @@ -4,7 +4,7 @@ ext=${file/*.} range=10000 filename="/var/www/www.openmamba.org/$file" filename_check=`readlink -f $filename` -[ "${filename_check:0:27}" = "/mnt/sdc1/ftp/pub/openmamba" ] || exit 0 +[ "${filename_check:0:22}" = "/var/ftp/pub/openmamba" ] || exit 0 if [ "$page" ]; then [ $page -gt 0 ] || page=1 else