[
https://issues.apache.org/jira/browse/OFBIZ-9973?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16244719#comment-16244719 ]
Jacques Le Roux commented on OFBIZ-9973:
----------------------------------------
At revision: 1814642 in trunk and r1814646 in R16.11 I fixed 2 cases FB reported.
They both relate to a request parameter that could be corrupted. They are respectively fixed using URLEncoder.encode() and File.getCanonicalFile()
Remains not fixed issues related with possible SQL injections that I'll possibly look at later...
--
This message was sent by Atlassian JIRA
(v6.4.14#64029)