bug in autoindex module

Edho P Arief edhoprima at gmail.com
Tue Dec 29 13:20:31 MSK 2009


Don't know if found by someone else, but I find this bug today in
autoindex module.

Basically, the file/dirname is not escaped properly.

To reproduce:
- enable autoindex in a directory
- create file with name "some<em>thing" in the directory
- view the (broken) directory list in web

-- 
O< ascii ribbon campaign - stop html mail - www.asciiribbon.org



More information about the nginx mailing list