From 1c13821ba1a7aa98f5888d5f4a99e73d441bab69 Mon Sep 17 00:00:00 2001 From: e Date: Wed, 19 Aug 2015 19:51:25 -0700 Subject: [PATCH] Fix file inclusion vulnerability --- test/inc/get-raw-javascript.php | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/test/inc/get-raw-javascript.php b/test/inc/get-raw-javascript.php index e7dec32..11c295b 100755 --- a/test/inc/get-raw-javascript.php +++ b/test/inc/get-raw-javascript.php @@ -3,7 +3,10 @@ header('Content-Type: application/javascript'); $url = $_GET['file']; - +$urlParts = parse_url($url); +if ($urlParts['scheme'] === "file") { + exit; +} $ch = curl_init($url); curl_exec($ch); curl_close($ch);