WordPress.org

Make WordPress Core

Ticket #22813: 22813-ms-files.diff

File 22813-ms-files.diff, 550 bytes (added by jamescollins, 5 years ago)
  • wp-includes/ms-files.php

     
    2323        die( '404 — File not found.' );
    2424}
    2525
    26 $file = rtrim( BLOGUPLOADDIR, '/' ) . '/' . str_replace( '..', '', $_GET[ 'file' ] );
     26$file = rtrim( BLOGUPLOADDIR, '/' ) . '/' . str_replace( array( '..', ' ' ), array( '', '+' ), $_GET['file'] );
    2727if ( !is_file( $file ) ) {
    2828        status_header( 404 );
    2929        die( '404 — File not found.' );