Skip to content

Commit

Permalink
path check
Browse files Browse the repository at this point in the history
  • Loading branch information
usmannasir committed Jan 17, 2020
1 parent 050c020 commit b88922e
Showing 1 changed file with 5 additions and 0 deletions.
5 changes: 5 additions & 0 deletions filemanager/filemanager.py
Original file line number Diff line number Diff line change
Expand Up @@ -272,6 +272,11 @@ def readFileContents(self):
domainName = self.data['domainName']
website = Websites.objects.get(domain=domainName)

pathCheck = '/home/%s' % (domainName)

if self.data['fileName'].find(pathCheck) == -1:
return self.ajaxPre(0, 'Not allowed.')

command = 'cat ' + self.returnPathEnclosed(self.data['fileName'])
finalData['fileContents'] = ProcessUtilities.outputExecutioner(command, website.externalApp)

Expand Down

0 comments on commit b88922e

Please sign in to comment.