Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
S
slm-fileview
Project
Project
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
梁杰芳
slm-fileview
Commits
922e1e6a
Commit
922e1e6a
authored
Jun 23, 2021
by
陈精华
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
修复压缩文件目录穿越漏洞
parent
79341b2c
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
2 additions
and
2 deletions
+2
-2
CompressFileReader.java
...r/src/main/java/cn/keking/service/CompressFileReader.java
+2
-2
No files found.
server/src/main/java/cn/keking/service/CompressFileReader.java
View file @
922e1e6a
...
...
@@ -55,7 +55,7 @@ public class CompressFileReader {
List
<
Map
<
String
,
ZipArchiveEntry
>>
entriesToBeExtracted
=
new
LinkedList
<>();
while
(
entries
.
hasMoreElements
())
{
ZipArchiveEntry
entry
=
entries
.
nextElement
();
String
fullName
=
entry
.
getName
();
String
fullName
=
entry
.
getName
()
.
replaceAll
(
"//"
,
""
).
replaceAll
(
"\\\\"
,
""
)
;
int
level
=
fullName
.
split
(
archiveSeparator
).
length
;
// 展示名
String
originName
=
getLastFileName
(
fullName
,
archiveSeparator
);
...
...
@@ -151,7 +151,7 @@ public class CompressFileReader {
List
<
Map
<
String
,
SevenZArchiveEntry
>>
entriesToBeExtracted
=
new
ArrayList
<>();
while
(
newEntries
.
hasMoreElements
())
{
SevenZArchiveEntry
entry
=
newEntries
.
nextElement
();
String
fullName
=
entry
.
getName
();
String
fullName
=
entry
.
getName
()
.
replaceAll
(
"//"
,
""
).
replaceAll
(
"\\\\"
,
""
)
;
int
level
=
fullName
.
split
(
archiveSeparator
).
length
;
// 展示名
String
originName
=
getLastFileName
(
fullName
,
archiveSeparator
);
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment