summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rwxr-xr-xpage.cgi10
1 files changed, 7 insertions, 3 deletions
diff --git a/page.cgi b/page.cgi
index 5464789e7..a6a198d8b 100755
--- a/page.cgi
+++ b/page.cgi
@@ -66,9 +66,13 @@ my $template = Bugzilla->template;
my $id = $cgi->param('id');
if ($id) {
- # Split into name and ctype, but be careful not to allow directory
- # traversal.
- $id =~ /^([\w\-\/]+)\.(\w+)$/;
+ # Be careful not to allow directory traversal.
+ if ($id =~ /\.\./) {
+ # two dots in a row is bad
+ ThrowCodeError("bad_page_cgi_id", { "page_id" => $id });
+ }
+ # Split into name and ctype.
+ $id =~ /^([\w\-\/\.]+)\.(\w+)$/;
if (!$2) {
# if this regexp fails to match completely, something bad came in
ThrowCodeError("bad_page_cgi_id", { "page_id" => $id });