servnest/pg-view/reg
Miraty 7f7bcadb58 Fix important vulnerability in reg/ds.php + exescape
In page reg/ds.php, POST parameter 'key' was directly sent to shell, allowing for remote arbitrary commands execution.

This commit fixes this vulnerability, and uses a new function to automatically escape every shell command arguments as an additional generic protection.
2023-06-19 02:15:43 +02:00
..
ds.php Fix important vulnerability in reg/ds.php + exescape 2023-06-19 02:15:43 +02:00
glue.php feature: reg: allow multiple suffixes 2023-01-23 01:14:59 +01:00
index.php Split accounts capabilities; Info about rate limit 2023-05-02 19:30:53 +02:00
ns.php --- > — 2023-01-21 04:16:02 +01:00
print.php css: "text-align: right" for domains in tables 2023-01-23 01:39:18 +01:00
register.php Display string rules, reg: allow "-" for subdomains 2023-06-05 00:18:10 +02:00
transfer.php Niver > ServNest 2023-01-29 21:09:00 +01:00
unregister.php reg: Delay at unregistration; Display domain history 2023-03-25 16:26:05 +01:00