From 08cc7f673c377bf88897743e340097e93f1e95f4 Mon Sep 17 00:00:00 2001 From: ftimme <ft@falkotimme.com> Date: Wed, 16 Jan 2013 09:30:05 -0500 Subject: [PATCH] - Changed regex for redirect path (Web sites, subdomains, vhost subdomains, alias domains) and web folder (vhost subdomains) so that ".." is not allowed (in order to prevent path traversals). - nginx: don't allow folders for proxy redirects (subdomains and alias domains); URL is required. - nginx: modified rewriting. --- interface/web/admin/templates/software_package_list.htm | 6 +++--- 1 files changed, 3 insertions(+), 3 deletions(-) diff --git a/interface/web/admin/templates/software_package_list.htm b/interface/web/admin/templates/software_package_list.htm index f9e1a25..d030e5e 100644 --- a/interface/web/admin/templates/software_package_list.htm +++ b/interface/web/admin/templates/software_package_list.htm @@ -6,7 +6,7 @@ <div class="pnl_toolsarea"> <fieldset><legend>{tmpl_var name="toolsarea_head_txt"}</legend> <div class="buttons"> - <button class="button iconstxt icoAdd" type="button" onClick="loadContent('admin/software_package_list.php?action=repoupdate');"> + <button class="button iconstxt icoAdd" type="button" onclick="loadContent('admin/software_package_list.php?action=repoupdate');"> <span>{tmpl_var name="repoupdate_txt"}</span> </button> </div> @@ -22,7 +22,7 @@ <th class="tbl_col_package_title" scope="col"><tmpl_var name="package_title_txt"></th> <th class="tbl_col_package_description" scope="col"><tmpl_var name="package_description_txt"></th> <th class="tbl_col_package_description" scope="col"><tmpl_var name="package_id_txt"></th> - <th class="tbl_col_buttons" scope="col"> </th> + <th class="tbl_col_limit" scope="col">{tmpl_var name='search_limit'}</th> </tr> </thead> <tbody> @@ -32,7 +32,7 @@ <td class="tbl_col_package_title">{tmpl_var name="package_title"}</td> <td class="tbl_col_package_description">{tmpl_var name="package_description"}</td> <td class="tbl_col_package_description">ispapp{tmpl_var name="package_id"}</td> - <td class="tbl_col_buttons"> + <td class="tbl_col_buttons"> <a class="button icons16 icoDelete" href="javascript: del_record('admin/software_package_del.php?software_update_inst_id={tmpl_var name="software_update_inst_id"}','{tmpl_var name='delete_confirmation'}');"><span>{tmpl_var name='delete_txt'}</span></a> </td> </tr> -- Gitblit v1.9.1