diff --git a/JavaSource/gov/noaa/pmel/tmap/las/filter/RequestInputFilter.java b/JavaSource/gov/noaa/pmel/tmap/las/filter/RequestInputFilter.java index 78e080ee..67fdf88e 100644 --- a/JavaSource/gov/noaa/pmel/tmap/las/filter/RequestInputFilter.java +++ b/JavaSource/gov/noaa/pmel/tmap/las/filter/RequestInputFilter.java @@ -418,7 +418,11 @@ public boolean validateTemplateAndImage(HttpServletRequest request) { if (v.toLowerCase().contains(">") || v.toLowerCase().contains("<") || v.toLowerCase().contains("script") || + v.toLowerCase().contains("/") || + v.toLowerCase().contains("%") || v.toLowerCase().contains("..") ) { + return false; + } if ( v.equals(vm[i]) ) { return true; } @@ -429,7 +433,6 @@ public boolean validateTemplateAndImage(HttpServletRequest request) { v.toLowerCase().contains("refresh") || v.toLowerCase().contains("equiv") ) { ->>>>>>> 9afbb8887c0051a06c31109e97022991c57db476 return false; } }