From 1087f7e873dc29594e0b7d8bf9b12a81358aa039 Mon Sep 17 00:00:00 2001 From: L1nyz-tel Date: Fri, 8 Mar 2024 22:43:56 +0800 Subject: [PATCH] =?UTF-8?q?fix:=20=E8=A7=A3=E5=86=B3=E5=91=BD=E4=BB=A4?= =?UTF-8?q?=E6=B3=A8=E5=85=A5waf=E8=A2=AB=E7=BB=95=E8=BF=87=E7=9A=84?= =?UTF-8?q?=E9=97=AE=E9=A2=98=20(#4131)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- backend/utils/cmd/cmd.go | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/backend/utils/cmd/cmd.go b/backend/utils/cmd/cmd.go index ec1e0343636b..fa290024ebf0 100644 --- a/backend/utils/cmd/cmd.go +++ b/backend/utils/cmd/cmd.go @@ -177,7 +177,8 @@ func CheckIllegal(args ...string) bool { for _, arg := range args { if strings.Contains(arg, "&") || strings.Contains(arg, "|") || strings.Contains(arg, ";") || strings.Contains(arg, "$") || strings.Contains(arg, "'") || strings.Contains(arg, "`") || - strings.Contains(arg, "(") || strings.Contains(arg, ")") || strings.Contains(arg, "\"") { + strings.Contains(arg, "(") || strings.Contains(arg, ")") || strings.Contains(arg, "\"") || + strings.Contains(arg, "\n") || strings.Contains(arg, "\r") { return true } }