browse-everything
browse-everything copied to clipboard
Ensure that relative or absolute paths are not passed to the configuration
Otherwise a carefully crafted requests could pull any file on the server.
Can you give an example of such a request? It is more than just ../../../etc/passwd, right?
That's basically what I was getting at. There should not be a way to pass an absolute or relative path that escapes the configured base.