Make WordPress Core

Opened 16 years ago

Closed 16 years ago

Last modified 16 years ago

#14594 closed defect (bug) (fixed)

Header injection in ms-files.php?

Reported by: Denis-de-Bernardy Owned by:
Priority: normal Milestone: 3.1
Component: Security Version: 3.0.1
Severity: normal Keywords:
Cc: Focuses:

Description

http://core.trac.wordpress.org/browser/trunk/wp-includes/ms-files.php?rev=14609#L41

Isn't there any potential to send raw, unfiltered data in this line?

Change History (4)

#1 @Denis-de-Bernardy
16 years ago

  • Resolutionfixed
  • Status newclosed

#2 @Denis-de-Bernardy
16 years ago

There might still be some potential for injections, though. Unit tests would be good...

#3 @hakre
16 years ago

Related: #14450

#4 @nacin
16 years ago

  • Milestone Awaiting Review3.1
Note: See TracTickets for help on using tickets.