mirror of
https://github.com/prasathmani/tinyfilemanager.git
synced 2026-04-27 11:25:54 +03:00
[GH-ISSUE #187] view file is insecure #131
Labels
No labels
Feature
Feature
Is It Really an Issue?
Need More Info
Request
Security
bug
duplicate
enhancement
enhancement
help wanted
invalid
pull-request
question
suggestion
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/tinyfilemanager#131
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @satyr-software on GitHub (Jun 14, 2019).
Original GitHub issue: https://github.com/prasathmani/tinyfilemanager/issues/187
File exclusion mask is applied on listing files, but not on views:
Short test:
Expected result:
Fix:
if ($file == '' || !is_file($path . '/' . $file) || in_array($file, $GLOBALS['exclude_items'])) {
Just before:
fm_set_msg('File not found', 'error');
@prasathmani commented on GitHub (Jul 23, 2019):
@satyr-software added your suggestion.