Skip to content

Conversation

@birep
Copy link

@birep birep commented May 29, 2019

While it would be nice if we could trust people not to include example files on live servers, a google search will reveal many people are serving RelativePath.Example1.php, including anyone running a here-unnamed CMS which includes this file in a subdirectory of the webroot.

The proposed changes simply escape the user input, closing an xss vulnerability.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant