Details
-
Bug
-
Resolution: Fixed
-
Blocker
-
3.5-milestone-1
-
Unit
-
Unknown
-
N/A
-
N/A
-
Description
Steps to reproduce:
- Activate the office server
- Upload an arbitrary file with the extension .doc, e.g., to your user profile (you can use a regular plain text file, only the extension seems to matter).
- Use the attachment move feature to rename the file to ../../../../../home/michael/Hello from XWiki.txt where the latter part is the location of a file you want to write on the server. The number of ../ depends on the directory depth, the provided example should work on Linux with the demo distribution.
- Click the "preview" link to trigger the office converter
Expected result:
A preview of the office file is displayed.
Actual result:
An error is displayed and but the office file is written to the specified location. This can most likely be used to override xwiki.cfg and set the superadmin password to gain superadmin access (not tried yet).
Attachments
Issue Links
- is related to
-
XWIKI-7506 Some code is still cleaning the attachment name
- Closed
- links to