From: garvinhicking Date: Mon, 9 May 2005 08:10:25 +0000 (+0000) Subject: disallow "." files like .htaccess. X-Git-Tag: 0.9~479 X-Git-Url: http://git.mjollnir.org/gw?a=commitdiff_plain;h=86f6940b48bf00579b081ddac59aee69261fd1a9;p=s9y.git disallow "." files like .htaccess. Sebastian, Tom - see my mail about this issue. --- diff --git a/include/admin/images.inc.php b/include/admin/images.inc.php index 4d1e958..fdedb81 100644 --- a/include/admin/images.inc.php +++ b/include/admin/images.inc.php @@ -125,7 +125,7 @@ switch ($serendipity['GET']['adminAction']) { $tindex = 1; } - if ($serendipity['serendipityUserlevel'] < USERLEVEL_ADMIN && preg_match('@\.(php[34]?|[ps]html?)$@i', $tfile)) { + if ($serendipity['serendipityUserlevel'] < USERLEVEL_ADMIN && (preg_match('@\.(php[34]?|[ps]html?)$@i', $tfile) || preg_match('@^\.@', $tfile)) { printf(ERROR_FILE_FORBIDDEN, $tfile); break; }