* fixed Issue 144: Path traversal access

git-svn-id: http://redmine-dmsf.googlecode.com/svn/trunk/redmine_dmsf@234 5e329b0b-a2ee-ea63-e329-299493fc886d
This commit is contained in:
vit.jonas@gmail.com 2011-09-18 08:28:59 +00:00
parent bf38bdaa03
commit 2627b392e0

View File

@ -93,8 +93,8 @@ class DmsfUploadController < ApplicationController
new_revision.minor_version = last_revision.minor_version
new_revision.workflow = last_revision.workflow
end
commited_disk_filepath = "#{DmsfHelper.temp_dir}/#{commited_file["disk_filename"]}"
commited_disk_filepath = "#{DmsfHelper.temp_dir}/#{commited_file["disk_filename"].gsub(/[\/\\]/,'')}"
new_revision.folder = @folder
new_revision.file = file