Skip to content

Commit

Permalink
#U4-5901 Fixed Due in version 7.2.0
Browse files Browse the repository at this point in the history
Remote Code Execution
  • Loading branch information
nul800sebastiaan committed Nov 27, 2014
1 parent d8909fe commit cad0650
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 2 deletions.
2 changes: 1 addition & 1 deletion src/Umbraco.Web.UI/config/umbracoSettings.Release.config
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@
<MacroErrors>inline</MacroErrors>

<!-- These file types will not be allowed to be uploaded via the upload control for media and content -->
<disallowedUploadFiles>ashx,aspx,ascx,config,cshtml,vbhtml,asmx,air,axd,swf,xml,html.htm,svg</disallowedUploadFiles>
<disallowedUploadFiles>ashx,aspx,ascx,config,cshtml,vbhtml,asmx,air,axd,swf,xml,html.htm,svg,php</disallowedUploadFiles>

<!-- Defines the default document type property used when adding properties in the back-office (if missing or empty, defaults to Textstring -->
<defaultDocumentTypeProperty>Textstring</defaultDocumentTypeProperty>
Expand Down
2 changes: 1 addition & 1 deletion src/Umbraco.Web.UI/config/umbracoSettings.config
Original file line number Diff line number Diff line change
Expand Up @@ -98,7 +98,7 @@
<MacroErrors>throw</MacroErrors>

<!-- These file types will not be allowed to be uploaded via the upload control for media and content -->
<disallowedUploadFiles>ashx,aspx,ascx,config,cshtml,vbhtml,asmx,air,axd,swf,xml,html.htm,svg</disallowedUploadFiles>
<disallowedUploadFiles>ashx,aspx,ascx,config,cshtml,vbhtml,asmx,air,axd,swf,xml,html.htm,svg,php</disallowedUploadFiles>

<!-- Defines the default document type property used when adding properties in the back-office (if missing or empty, defaults to Textstring -->
<defaultDocumentTypeProperty>Textstring</defaultDocumentTypeProperty>
Expand Down

0 comments on commit cad0650

Please sign in to comment.