mushorg / glastopf

Web Application Honeypot
http://glastopf.org
551 stars 172 forks source link

Fixing path checking in classification/request.py #273

Closed hun7err closed 8 years ago

hun7err commented 8 years ago

Analogically to file_server.py and the last PR, there was a possibility of path traversal in file_exists (although without actually retrieving file content).

katkad commented 8 years ago

I cherry-picked your commit into master.

Thank you very much for contribution :sparkles: