MantisBT: master 4f61786b

Author Committer Branch Timestamp Parent
Damien Regad Damien Regad master 2014-05-30 15:04 master ee3e36c8
Changeset

Improve plugin path regex to avoid arbitrary includes

The path and filename components are not allowed to start with a '.',
which prevents uses like ../../../etc/password

mod - plugin_file.php Diff File