Skip to content
Browse files

Fix directory traversal fixing RegExp

  • Loading branch information...
1 parent a1a1017 commit 7557af3db7db392fc12bdab19e4bc27d0bf92d56 @adrianheine adrianheine committed Sep 1, 2011
Showing with 1 addition and 1 deletion.
  1. +1 −1 node/server.js
View
2 node/server.js
@@ -100,7 +100,7 @@ async.waterfall([
{
res.header("Server", serverName);
var filePath = path.normalize(__dirname + "/.." +
- req.url.replace(/\./g, '').split("?")[0]);
+ req.url.replace(/\.\./g, '').split("?")[0]);
res.sendfile(filePath, { maxAge: exports.maxAge });
});

0 comments on commit 7557af3

Please sign in to comment.
Something went wrong with that request. Please try again.