Skip to content

Commit 8cae64d

Browse files
committed
Merge pull request #75 from cese/master
Fix security issue (arbitrary file unlink)
2 parents 0b4db7e + db66042 commit 8cae64d

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

index.php

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -321,6 +321,10 @@ function processPasteDelete($pasteid,$deletetoken)
321321
return array('','Paste does not exist, has expired or has been deleted.','');
322322
}
323323
}
324+
else
325+
{
326+
return array('','Invalid data','');
327+
}
324328

325329
if (!slow_equals($deletetoken, hash_hmac('sha1', $pasteid , getServerSalt()))) // Make sure token is valid.
326330
{

0 commit comments

Comments
 (0)