From a276dfba7a4228aef22af1c669bec8012715f4a4 Mon Sep 17 00:00:00 2001 From: Leo-Andres Hofmann Date: Thu, 13 May 2021 11:27:04 +0200 Subject: [PATCH] getrrdimage.cgi: Allow more non-word characters in the URL MIME-Version: 1.0 Content-Type: text/plain; charset=utf8 Content-Transfer-Encoding: 8bit As discussed in bug #12615 Signed-off-by: Leo-Andres Hofmann Reviewed-by: Adolf Belka Reviewed-by: Peter Müller Signed-off-by: Michael Tremer --- html/cgi-bin/getrrdimage.cgi | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/html/cgi-bin/getrrdimage.cgi b/html/cgi-bin/getrrdimage.cgi index 34ee4bf7aa..c08247c571 100644 --- a/html/cgi-bin/getrrdimage.cgi +++ b/html/cgi-bin/getrrdimage.cgi @@ -50,7 +50,7 @@ my $graph = $query{'graph'}; my $range = lc $query{'range'}; # lower case # Check parameters -unless(($origin =~ /^\w+?\.cgi$/) && ($graph =~ /^[\w-]+?$/) && ($range ~~ @Graphs::time_ranges)) { +unless(($origin =~ /^\w+?\.cgi$/) && ($graph =~ /^[\w\-.,; ]+?$/) && ($range ~~ @Graphs::time_ranges)) { # Send HTTP headers _start_png_output(); -- 2.39.2