Skip to content

Commit 2971e22

Browse files
committed
Stop escaping characters
1 parent 5cda5d0 commit 2971e22

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

cgi-bin/page.fcgi

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -446,6 +446,7 @@ sub doit
446446
eval {
447447
my $page = $info->param('page');
448448
$page =~ s/#.*$//;
449+
$page =~ s/\\//g; # I don't know what you're trying to escape or why, but I'm not going to let you
449450
if($page =~ /\//) {
450451
# Block "page=/etc/passwd" and "page=http://www.google.com"
451452
$logger->info("Blocking '/' in $page");

0 commit comments

Comments
 (0)