Closed miekg closed 6 years ago
Add a 'safeInclude' flag that only allows relative includes and no .. in the paths. This is a simple check.
..
A more advanced safe include would be to only allow files below the initial file being work on.
This is been done, only files below the current one are allowed, unless -unsafe is given (mparser.UnsafeInclude)
mparser.UnsafeInclude
Add a 'safeInclude' flag that only allows relative includes and no
..
in the paths. This is a simple check.A more advanced safe include would be to only allow files below the initial file being work on.