Permalink
Browse files

Protect replacement of "/../.." or "/./.." for "/" during import.

  • Loading branch information...
1 parent e1b374b commit fe81dbc9c22ff9997ce19d8d65d671533fd5f583 @KendallHopkins KendallHopkins committed with Oct 27, 2011
Showing with 1 addition and 1 deletion.
  1. +1 −1 min/lib/Minify/ImportProcessor.php
View
2 min/lib/Minify/ImportProcessor.php
@@ -148,7 +148,7 @@ private function _urlCB($m)
$url = str_replace('/./', '/', $url);
// inspired by patch from Oleg Cherniy
do {
- $url = preg_replace('@/[^/]+/\\.\\./@', '/', $url, 1, $changed);
+ $url = preg_replace('@/(?!\\.\\.?)[^/]+/\\.\\.@', '/', $url, 1, $changed);
} while ($changed);
}
}

0 comments on commit fe81dbc

Please sign in to comment.