Uploaded image for project: 'JSPWiki'
  1. JSPWiki
  2. JSPWIKI-5

VersioningFileProvider allows creation of pages that start with a dot

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 2.5.139-beta
    • 2.8
    • Core & storage
    • None
    • Ubuntu Linux, JDK 1.5

    Description

      By manipulating the JSP fields directly, it's possible to upload a file (e.g. ".."), which ends up in the page directory under the name "..-att". This does not otherwise affect JSPWiki operation, but it does make that data inaccessible and invisible.

      Proposal is to make sure that dots should also be escaped when saving a file.

      Attachments

        Activity

          People

            jalkanen Janne Jalkanen
            jalkanen Janne Jalkanen
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: