Michael Tremer
7f6257e0a4
backup: Sanitise FILE parameter
...
This parameter was passed to some shell commands without any
sanitisation which allowed an attacker who was authenticated to
the web UI to download arbitrary files from some directories
and delete any file from the filesystem.
References: #11830
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-09-13 15:03:59 +01:00
..
2008-02-05 19:22:05 +00:00
2017-09-22 19:00:04 +01:00
2018-08-14 11:48:03 +01:00
2014-04-09 14:19:16 +02:00
2014-02-15 16:41:40 +01:00
2018-09-13 15:03:59 +01:00
2008-08-16 17:44:44 +02:00
2018-01-10 16:44:04 +00:00
2016-04-08 15:54:53 +01:00
2017-12-02 12:24:29 +00:00
2015-09-21 16:40:41 +01:00
2017-11-13 22:37:19 +00:00
2018-08-05 11:10:28 +01:00
2015-04-26 16:52:52 +02:00
2015-10-21 17:34:41 +01:00
2016-09-24 12:25:46 +01:00
2016-08-06 19:34:39 +01:00
2018-05-22 20:31:12 +01:00
2017-10-02 19:27:52 +01:00
2018-01-07 19:18:33 +00:00
2018-08-22 14:46:10 +01:00
2018-08-24 11:44:45 +01:00
2015-05-12 20:39:44 +02:00
2014-03-05 23:53:21 +01:00
2018-07-03 10:33:43 +01:00
2014-02-15 15:51:41 +01:00
2017-11-29 12:01:30 +00:00
2016-09-12 20:52:51 +01:00
2018-08-16 18:54:06 +01:00
2018-08-23 17:34:50 +01:00
2017-12-02 12:24:19 +00:00
2017-04-18 11:22:18 +01:00
2015-09-21 16:40:41 +01:00
2015-11-10 18:38:56 +00:00
2014-02-18 18:48:57 +01:00
2014-04-12 12:18:57 +02:00
2010-12-12 20:40:56 +01:00
2014-06-06 10:45:59 +02:00
2015-09-21 16:40:41 +01:00
2009-10-27 23:49:03 +01:00
2017-11-29 12:05:43 +00:00
2013-11-08 14:32:08 +01:00
2017-11-29 11:59:49 +00:00
2015-04-14 14:00:47 +02:00
2017-03-15 13:45:05 +00:00
2016-04-20 16:14:14 +01:00
2018-07-10 18:40:39 +01:00
2014-02-15 16:54:38 +01:00
2018-08-27 07:29:19 +01:00
2016-09-08 12:58:47 +01:00
2018-07-01 12:38:48 +01:00
2018-03-06 15:13:16 +00:00
2018-05-09 14:49:48 +01:00
2017-11-07 16:20:29 +00:00
2016-09-27 19:38:38 +02:00
2007-08-29 13:25:32 +00:00
2016-08-06 19:30:14 +01:00
2014-02-04 16:13:57 +01:00
2013-09-07 16:23:50 +02:00
2017-03-15 13:45:05 +00:00
2015-09-21 16:40:41 +01:00
2017-11-07 16:14:36 +00:00
2016-10-02 15:13:55 +01:00
2015-09-21 16:40:41 +01:00
2014-02-22 12:13:02 +01:00
2015-09-21 16:40:41 +01:00
2018-08-23 17:34:50 +01:00
2015-09-21 16:40:41 +01:00
2016-01-19 00:06:30 +00:00
2015-09-21 16:40:41 +01:00
2017-05-16 15:05:25 +02:00
2017-09-20 22:23:19 +01:00