Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
Y
yii2
Project
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
PSDI Army
yii2
Commits
f9dee9c9
Commit
f9dee9c9
authored
Jan 28, 2014
by
Carsten Brandt
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Fixed an issue with Filehelper and not accessable directories
which resulted in endless loop
http://www.yiiframework.com/forum/index.php/topic/50982-cfilehelper-bug-security-flaw/
parent
f1a674b9
Show whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
7 additions
and
0 deletions
+7
-0
CHANGELOG.md
framework/CHANGELOG.md
+1
-0
BaseFileHelper.php
framework/helpers/BaseFileHelper.php
+6
-0
No files found.
framework/CHANGELOG.md
View file @
f9dee9c9
...
@@ -45,6 +45,7 @@ Yii Framework 2 Change Log
...
@@ -45,6 +45,7 @@ Yii Framework 2 Change Log
-
Bug: Fixed the issue that query cache returns the same data for the same SQL but different query methods (qiangxue)
-
Bug: Fixed the issue that query cache returns the same data for the same SQL but different query methods (qiangxue)
-
Bug: Fixed URL parsing so it's now properly giving 404 for URLs like
`http://example.com//////site/about`
(samdark)
-
Bug: Fixed URL parsing so it's now properly giving 404 for URLs like
`http://example.com//////site/about`
(samdark)
-
Bug: Fixed
`HelpController::getModuleCommands`
issue where it attempts to scan a module's controller directory when it doesn't exist (jom)
-
Bug: Fixed
`HelpController::getModuleCommands`
issue where it attempts to scan a module's controller directory when it doesn't exist (jom)
-
Bug: Fixed an issue with Filehelper and not accessable directories which resulted in endless loop (cebe)
-
Enh #46: Added Image extension based on
[
Imagine library
](
http://imagine.readthedocs.org
)
(
tonydspaniard
)
-
Enh #46: Added Image extension based on
[
Imagine library
](
http://imagine.readthedocs.org
)
(
tonydspaniard
)
-
Enh #364: Improve Inflector::slug with
`intl`
transliteration. Improved transliteration char map. (tonydspaniard)
-
Enh #364: Improve Inflector::slug with
`intl`
transliteration. Improved transliteration char map. (tonydspaniard)
-
Enh #797: Added support for validating multiple columns by
`UniqueValidator`
and
`ExistValidator`
(qiangxue)
-
Enh #797: Added support for validating multiple columns by
`UniqueValidator`
and
`ExistValidator`
(qiangxue)
...
...
framework/helpers/BaseFileHelper.php
View file @
f9dee9c9
...
@@ -185,6 +185,9 @@ class BaseFileHelper
...
@@ -185,6 +185,9 @@ class BaseFileHelper
}
}
$handle
=
opendir
(
$src
);
$handle
=
opendir
(
$src
);
if
(
$handle
===
false
)
{
throw
new
InvalidParamException
(
'Unable to open directory: '
.
$src
);
}
while
((
$file
=
readdir
(
$handle
))
!==
false
)
{
while
((
$file
=
readdir
(
$handle
))
!==
false
)
{
if
(
$file
===
'.'
||
$file
===
'..'
)
{
if
(
$file
===
'.'
||
$file
===
'..'
)
{
continue
;
continue
;
...
@@ -293,6 +296,9 @@ class BaseFileHelper
...
@@ -293,6 +296,9 @@ class BaseFileHelper
}
}
$list
=
[];
$list
=
[];
$handle
=
opendir
(
$dir
);
$handle
=
opendir
(
$dir
);
if
(
$handle
===
false
)
{
throw
new
InvalidParamException
(
'Unable to open directory: '
.
$dir
);
}
while
((
$file
=
readdir
(
$handle
))
!==
false
)
{
while
((
$file
=
readdir
(
$handle
))
!==
false
)
{
if
(
$file
===
'.'
||
$file
===
'..'
)
{
if
(
$file
===
'.'
||
$file
===
'..'
)
{
continue
;
continue
;
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment