WordPress.org

Make WordPress Core

Ticket #22813: 22813-ms-files.diff

File 22813-ms-files.diff, 550 bytes (added by jamescollins, 2 years ago)
  • wp-includes/ms-files.php

     
    2323        die( '404 — File not found.' ); 
    2424} 
    2525 
    26 $file = rtrim( BLOGUPLOADDIR, '/' ) . '/' . str_replace( '..', '', $_GET[ 'file' ] ); 
     26$file = rtrim( BLOGUPLOADDIR, '/' ) . '/' . str_replace( array( '..', ' ' ), array( '', '+' ), $_GET['file'] ); 
    2727if ( !is_file( $file ) ) { 
    2828        status_header( 404 ); 
    2929        die( '404 — File not found.' );