c3d14e1fa5
- fix vulnerability in rewrite_relative_url() which prevented some URLs from being properly absolutized - fetch_file_contents: validate all URLs before requesting them - validate URLs: explicitly whitelist http and https scheme, forbid everything else - DiskCache/cached_url: only serve whitelisted content types (images, video) - simplify filename/URL handling code, remove and consolidate some less-used functions |
||
---|---|---|
.. | ||
autoload.php | ||
colors.php | ||
controls.php | ||
db-prefs.php | ||
db.php | ||
errorhandler.php | ||
functions.php | ||
login_form.php | ||
sanity_check.php | ||
sanity_config.php | ||
sessions.php |