From fb9ef8ecd38f26814fb61212a282420fd0f13d53 Mon Sep 17 00:00:00 2001 From: Stefan Brand Date: Tue, 11 Jan 2022 17:08:34 +0100 Subject: [PATCH] Prevent Path Traversal --- index.php | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/index.php b/index.php index ac2e1c1..32a34ab 100644 --- a/index.php +++ b/index.php @@ -43,8 +43,9 @@ if (isset($_SESSION['files']) - if ($r_imagedir === false || strcmp($r_imagedir, $r_basedir . DIRECTORY_SEPARATOR) !== 0) { + if ($r_imagedir === false || strpos($r_imagedir, $r_basedir . DIRECTORY_SEPARATOR) !== 0) { print_r($r_basedir); + print_r($r_imagedir); print "Path Traversal Detected!"; exit();