diff options
Fix URI validation bypasses (Phase 1.3 updated)
- Add url_decode function to handle percent-encoded sequences
- Check both raw and URL-decoded paths for traversal attacks
- Catch %2e%2e%2f (encoded ../) and similar bypasses
- Improved path traversal detection for patterns like /etc/../passwd
Fixes TPol-identified vulnerabilities:
- URL-encoded path traversal bypasses
- Missing path traversal detection in some patterns
Diffstat (limited to 'license/GPL-3.0-or-later.txt')
0 files changed, 0 insertions, 0 deletions
