Michael Tremer 7f6257e0a4 backup: Sanitise FILE parameter
This parameter was passed to some shell commands without any
sanitisation which allowed an attacker who was authenticated to
the web UI to download arbitrary files from some directories
and delete any file from the filesystem.

References: #11830

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-09-13 15:03:59 +01:00
2018-09-12 21:04:07 +02:00
2018-07-03 10:34:57 +01:00
2018-09-13 15:03:59 +01:00
2018-07-03 15:33:04 +01:00
2018-09-12 21:04:07 +02:00
2018-09-09 17:42:17 +01:00
2010-01-22 11:37:55 +01:00
Description
No description provided
101 MiB
Languages
Perl 70.4%
Shell 23%
C 4%
Python 0.6%
Makefile 0.5%
Other 1.4%