Skip to content

Valid hidden Joomla files/folders sometimes fail the filter #51

Open
@GeraintEdwards

Description

@GeraintEdwards

Steps to reproduce the issue

  1. Apply the path filter to the path

/var/www/vhosts/website-net/subdomain-website-net/._hiddenTemp

  1. Apply the path filter to the path

/var/www/vhosts/website.net/subdomain.website.net/._hiddenTemp

Expected result

  1. Should return the cleaned path

/var/www/vhosts/website-net/subdomain-website-net/._hiddenTemp

  1. Should return the cleaned path

/var/www/vhosts/website.net/subdomain.website.net/._hiddenTemp

Actual result

  1. Returns the path

/var/www/vhosts/website-net/subdomain-website-net/._hiddenTemp

  1. Returns an empty path

``

Additional comments

Plesk servers use the domain/subdomain pattern 2 so this is a live issue.

Additionally the use of hidden files/folders is a valid and security enhancing use case - setting the Joomla tmp or log directory to a hidden *nix folder is a good thing. Also can be used to install a hidden Joomla installation in an obscure and hidden sub-folder of a live site.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions