Re: SWISH-E 2.4.4 filters can not locate files

David L Norris <[email protected]> Wed, 18 Oct 2006 06:30:59 -0700 (PDT)
Newsgroups gmane.comp.web.swish-e
Message-ID <[email protected]>
On Tue, 2006-10-17 at 08:29 +0200, Ludovic Drolez wrote:
> On the contrary, the quoting is done to avoid problem with quotes in
> filenames (before that I was unable to index files with single quotes or
> double quotes, and specialy crafted filenames could lead to arbitrary
> command invocations :-( ).

Right, a file named something like '/path/to/'&& rm -Rf /'&&echo .pdf'
could erase files.

> Maybe something needs to be updated in the docs ?

Yes, ultimately the problem is that people are still using quotes around
filenames in their Filefilter directive.  Even if we switched to
fork-exec users would need to stop single-quoting their filenames in
that way.

-- 
 David L Norris
  http://webaugur.com/
  ICQ - 412039