]> Pileus Git - vpaste/commitdiff
security hole with pathinfo
authorAndy Spencer <andy753421@gmail.com>
Thu, 8 Oct 2009 05:14:29 +0000 (05:14 +0000)
committerAndy Spencer <andy753421@gmail.com>
Thu, 8 Oct 2009 05:14:29 +0000 (05:14 +0000)
index.cgi

index cdfaa82dd40f1c8d84688153d1f1facaeae8b3bb..a9f2465d54469bfbfb7cf2d8d10aba2768b0d917 100755 (executable)
--- a/index.cgi
+++ b/index.cgi
@@ -178,7 +178,7 @@ EOF
 }
 
 # Main
-pathinfo="${SCRIPT_URL/*vpaste\/}"
+pathinfo="${SCRIPT_URL/*\/}"
 
 if [ "$pathinfo" ]; then
        do_print "$pathinfo"