diff options
author | Jo-Philipp Wich <jo@mein.io> | 2022-01-19 16:32:52 +0100 |
---|---|---|
committer | Jo-Philipp Wich <jo@mein.io> | 2022-01-19 16:32:52 +0100 |
commit | 8752701b0d01a81d0bd0a735be733f24ad11ab69 (patch) | |
tree | 48741b61bb0a70dc78bdc815df7a67f1f14aeea1 /modules/luci-base/src/template_parser.c | |
parent | 35df2adaf8a2c5b4fa61f58049f409ca087c0547 (diff) |
luci-base: sys: prevent path traversal via sys.init routines
Filter the init script name parameter through fs.basename() to avoid
invoking paths outside of /etc/init.d/.
Reported-by: Graham R <gr348@cam.ac.uk>
Signed-off-by: Jo-Philipp Wich <jo@mein.io>
Diffstat (limited to 'modules/luci-base/src/template_parser.c')
0 files changed, 0 insertions, 0 deletions