Commit 9d283cf2 authored by Ruediger Pluem's avatar Ruediger Pluem
Browse files

* Prevent XSS attacks when using wildcards in the path of the FTP URL

  (CVE-2008-2939). Discovered by Marc Bevand of Rapid7.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@682868 13f79535-47bb-0310-9956-ffa450edef68
parent 7b80d265
Loading
Loading
Loading
Loading
+1 −0
Changes for modules/proxy/mod_proxy_ftp.c: 1 added line, 0 removed lines.
Original line number Diff line number Diff line
@@ -390,6 +390,7 @@ static apr_status_t proxy_send_dir_filter(ap_filter_t *f,
                                                           c->bucket_alloc));
        }
        if (wildcard != NULL) {
            wildcard = ap_escape_html(p, wildcard);
            APR_BRIGADE_INSERT_TAIL(out, apr_bucket_pool_create(wildcard,
                                                           strlen(wildcard), p,
                                                           c->bucket_alloc));