보안을 위해 RAR Wrapper 차단
This commit is contained in:
@ -3489,8 +3489,10 @@ function is_include_path_check($path='', $is_input='')
|
|||||||
{
|
{
|
||||||
if( $path ){
|
if( $path ){
|
||||||
if ($is_input){
|
if ($is_input){
|
||||||
|
// 장태진 @jtjisgod <jtjisgod@gmail.com> 추가
|
||||||
|
// 보안 목적 : rar wrapper 차단
|
||||||
|
|
||||||
if( stripos($path, 'php:') !== false || stripos($path, 'zlib:') !== false || stripos($path, 'bzip2:') !== false || stripos($path, 'zip:') !== false || stripos($path, 'data:') !== false || stripos($path, 'phar:') !== false ){
|
if( stripos($path, 'rar:') !== false || stripos($path, 'php:') !== false || stripos($path, 'zlib:') !== false || stripos($path, 'bzip2:') !== false || stripos($path, 'zip:') !== false || stripos($path, 'data:') !== false || stripos($path, 'phar:') !== false ){
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user