#401: Do not allow use of ".." in file upload/download service
---------------------+------------------------------------------------------
Reporter: fxp | Owner: geonetwork-devel@…
Type: defect | Status: new
Priority: major | Milestone: v2.7.0
Component: General | Version: v2.6.1
Keywords: |
---------------------+------------------------------------------------------
Fname parameter could contains ".." which is not safe in some
configuration.
Fixed in :
* 2.4.x : r6921
* 2.6.x : r6922
* trunk : r6923
--
Ticket URL: <http://trac.osgeo.org/geonetwork/ticket/401>
GeoNetwork opensource Developer website <http://trac.osgeo.org/geonetwork>
GeoNetwork opensource is a standards based, Free and Open Source catalog application to manage spatially referenced resources through the web. It provides powerful metadata editing and search functions as well as an embedded interactive web map viewer. This website contains information related to the development of the software.