lambdamoo
lambdamoo copied to clipboard
ctime() can read arbitrary files
The ctime()
built-in function allows a timezone to be passed as a second argument.
Surprisingly, an argument of the form “:path” will read the file described by the given path and attempt to parse it for timezone information. This may potentially be a security risk.