From 2328ad3103e577dd5e808b0a965825e7a4d1ccd7 Mon Sep 17 00:00:00 2001 From: e107steved Date: Wed, 30 May 2007 19:20:25 +0000 Subject: [PATCH] Bugtracker #3710 - image paths from forum RSS feed (and probably other plugins) --- e107_files/bbcode/img.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/e107_files/bbcode/img.bb b/e107_files/bbcode/img.bb index 1ba3de8db..7c200fdcf 100644 --- a/e107_files/bbcode/img.bb +++ b/e107_files/bbcode/img.bb @@ -25,7 +25,7 @@ foreach($imgParms as $k => $v) { } -if(file_exists(e_IMAGE."newspost_images/".$code_text)) +if((strpos($code_text,'../') === FALSE) && file_exists(e_IMAGE."newspost_images/".$code_text)) { $code_text = e_IMAGE."newspost_images/".$code_text; }