Changeset 38533
- Timestamp:
- 09/06/2016 06:03:57 PM (8 years ago)
- Location:
- branches/3.8
- Files:
-
- 2 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/3.8
-
branches/3.8/src/wp-admin/includes/class-wp-upgrader.php
r27923 r38533 1602 1602 wp_die( $uploads['error'] ); 1603 1603 1604 $this->filename = $_GET[$urlholder];1604 $this->filename = sanitize_file_name( $_GET[ $urlholder ] ); 1605 1605 $this->package = $uploads['basedir'] . '/' . $this->filename; 1606 1607 if ( 0 !== strpos( realpath( $this->package ), realpath( $uploads['basedir'] ) ) ) { 1608 wp_die( __( 'Please select a file' ) ); 1609 } 1606 1610 } 1607 1611 }
Note: See TracChangeset
for help on using the changeset viewer.