#16189 closed defect (bug) (duplicate)
Uploading files with more than one contiguous period should be disallowed
Reported by: |
|
Owned by: | |
---|---|---|---|
Milestone: | Priority: | normal | |
Severity: | normal | Version: | 3.1 |
Component: | Upload | Keywords: | |
Focuses: | Cc: |
Description
The file handler for multisite has a security http://core.trac.wordpress.org/browser/tags/3.0.4/wp-includes/ms-files.php#L26|measure which effectively bars the display of files with more than one contiguous period in the filename, e.g. my...file.jpg
. Seems a silly thing to name a file, but there we go.
If this is the case then we probably should disallow uploading files like this, so no-one can get themselves in a twist and upload files which are unviewable on their site.
The attached diff adds a check for more than one contiguous period in the filename, and disallows the upload if the test fails.
Attachments (1)
Change History (4)
Note: See
TracTickets for help on using
tickets.
Add a file upload test for more than one contiguous period