Skip to content

createthumb.php security / improvement #123

@rhaamo

Description

@rhaamo

I have in the user home a file like "watermark.png", I can generate a thumbnail by using an URL like :

/createthumb.php?filename=../watermark.png&size=320

Even something like this works:

/createthumb.php?filename=../../../usr/share/pixmaps/debian-logo.png&size=320

Even if it would not render anything other than an image type this seems to be a security issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions