* fixed Issue 144: Path traversal access
git-svn-id: http://redmine-dmsf.googlecode.com/svn/trunk/redmine_dmsf@234 5e329b0b-a2ee-ea63-e329-299493fc886d
This commit is contained in:
parent
bf38bdaa03
commit
2627b392e0
@ -93,8 +93,8 @@ class DmsfUploadController < ApplicationController
|
||||
new_revision.minor_version = last_revision.minor_version
|
||||
new_revision.workflow = last_revision.workflow
|
||||
end
|
||||
|
||||
commited_disk_filepath = "#{DmsfHelper.temp_dir}/#{commited_file["disk_filename"]}"
|
||||
|
||||
commited_disk_filepath = "#{DmsfHelper.temp_dir}/#{commited_file["disk_filename"].gsub(/[\/\\]/,'')}"
|
||||
|
||||
new_revision.folder = @folder
|
||||
new_revision.file = file
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user