Skip to content

Commit d21a6d4

Browse files
committed
Improved backup var validation
1 parent ba913ba commit d21a6d4

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

web/list/backup/index.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
unset($output);
2020
include($_SERVER['DOCUMENT_ROOT'].'/templates/admin/list_backup.html');
2121
} else {
22-
exec (VESTA_CMD."v-list-user-backup $user '".$_GET['backup']."' json", $output, $return_var);
22+
exec (VESTA_CMD."v-list-user-backup $user '".escapeshellarg($_GET['backup'])."' json", $output, $return_var);
2323
$data = json_decode(implode('', $output), true);
2424
$data = array_reverse($data,true);
2525
unset($output);

0 commit comments

Comments
 (0)