[wp-trac] [WordPress Trac] #48316: Changeset 46482 breaks upload when using ".." in upload_path.

WordPress Trac noreply at wordpress.org
Thu Nov 7 09:01:12 UTC 2019


#48316: Changeset 46482 breaks upload when using ".." in upload_path.
----------------------------+------------------------------
 Reporter:  xpoon           |       Owner:  (none)
     Type:  defect (bug)    |      Status:  reopened
 Priority:  normal          |   Milestone:  Awaiting Review
Component:  Filesystem API  |     Version:  trunk
 Severity:  major           |  Resolution:
 Keywords:                  |     Focuses:
----------------------------+------------------------------

Comment (by mpcube):

 The reasons for [46482] would be also intresting because of the fact, that
 it just prevents the creation of directories. I'm still allowed to place
 files in these paths that can't be created any more. I can not think of a
 situation where creating a direcory is a security problem but uploading a
 file to the same location is not.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/48316#comment:22>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list