servnest/pg-act/ht
Miraty 7f7bcadb58 Fix important vulnerability in reg/ds.php + exescape
In page reg/ds.php, POST parameter 'key' was directly sent to shell, allowing for remote arbitrary commands execution.

This commit fixes this vulnerability, and uses a new function to automatically escape every shell command arguments as an additional generic protection.
2023-06-19 02:15:43 +02:00
..
add-dns.php Fix important vulnerability in reg/ds.php + exescape 2023-06-19 02:15:43 +02:00
add-onion.php Fix important vulnerability in reg/ds.php + exescape 2023-06-19 02:15:43 +02:00
add-subdomain.php Display string rules, reg: allow "-" for subdomains 2023-06-05 00:18:10 +02:00
add-subpath.php Display string rules, reg: allow "-" for subdomains 2023-06-05 00:18:10 +02:00
del.php init.php + jobs + job to delete old testing accounts 2023-06-08 17:36:44 +02:00
keys.php Allow SSH keys authentication for SFTP(Go) 2023-06-15 03:35:42 +02:00