fix: tighten up detectPossibleDirectoryTraversal for Windows

This commit is contained in:
Connor Tumbleson 2024-01-17 06:11:22 -05:00
parent 841db5061a
commit 1b1c7f8f50
No known key found for this signature in database
GPG Key ID: C3CC0A201EC7DA75
1 changed files with 1 additions and 4 deletions

View File

@ -95,10 +95,7 @@ public class BrutIO {
}
public static boolean detectPossibleDirectoryTraversal(String entry) {
if (OSDetection.isWindows()) {
return entry.contains("..\\") || entry.contains("\\..");
}
return entry.contains("../") || entry.contains("/..");
return entry.contains("../") || entry.contains("/..") || entry.contains("..\\") || entry.contains("\\..");
}
public static String adaptSeparatorToUnix(String path) {