check file_exists
This commit is contained in:
parent
5f087b1689
commit
267303d4ce
6
show.php
6
show.php
@ -2,7 +2,11 @@
|
|||||||
|
|
||||||
$path = realpath($basedir . DIRECTORY_SEPARATOR . ltrim(urldecode($_SERVER["QUERY_STRING"]), '/'));
|
$path = realpath($basedir . DIRECTORY_SEPARATOR . ltrim(urldecode($_SERVER["QUERY_STRING"]), '/'));
|
||||||
|
|
||||||
if (strpos($path, $basedir) !== 0 || substr($path, -4) != ".cfg") {
|
if (
|
||||||
|
strpos($path, $basedir) !== 0
|
||||||
|
|| substr($path, -4) != ".cfg"
|
||||||
|
|| !file_exists($path)
|
||||||
|
) {
|
||||||
http_response_code(404);
|
http_response_code(404);
|
||||||
die("Fichier non trouvé");
|
die("Fichier non trouvé");
|
||||||
}
|
}
|
||||||
|
Loading…
x
Reference in New Issue
Block a user