tuxis-ie / nsedit

DNS Editor working with PowerDNS's new API
GNU General Public License v2.0
198 stars 55 forks source link

Potential security problem when checking authdb acessibility #186

Closed bajizs closed 3 years ago

bajizs commented 5 years ago

https://github.com/tuxis-ie/nsedit/blob/371eb417871c4e37293b84f5dda235dc40953987/index.php#L39

Not a good solution to send to browser (any user) where is the user database file. For example You move the database out of web folder, for better security, and You send information to user where is it.

If You want to make this test, better to test over self connection to the server, or check first it is in web folder or not.

vahem2lu commented 3 years ago

Maybe merge?