Better validation of the URL used in core HTTP requests.
git-svn-id: https://develop.svn.wordpress.org/trunk@30443 602fd350-edb4-49c9-b593-d223f7449a82
This commit is contained in:
parent
7e75ef00d2
commit
5db0ce11fb
@ -444,8 +444,9 @@ function send_origin_headers() {
|
|||||||
* @return mixed URL or false on failure.
|
* @return mixed URL or false on failure.
|
||||||
*/
|
*/
|
||||||
function wp_http_validate_url( $url ) {
|
function wp_http_validate_url( $url ) {
|
||||||
|
$original_url = $url;
|
||||||
$url = wp_kses_bad_protocol( $url, array( 'http', 'https' ) );
|
$url = wp_kses_bad_protocol( $url, array( 'http', 'https' ) );
|
||||||
if ( ! $url )
|
if ( ! $url || strtolower( $url ) !== strtolower( $original_url ) )
|
||||||
return false;
|
return false;
|
||||||
|
|
||||||
$parsed_url = @parse_url( $url );
|
$parsed_url = @parse_url( $url );
|
||||||
@ -455,7 +456,7 @@ function wp_http_validate_url( $url ) {
|
|||||||
if ( isset( $parsed_url['user'] ) || isset( $parsed_url['pass'] ) )
|
if ( isset( $parsed_url['user'] ) || isset( $parsed_url['pass'] ) )
|
||||||
return false;
|
return false;
|
||||||
|
|
||||||
if ( false !== strpos( $parsed_url['host'], ':' ) )
|
if ( false !== strpbrk( $parsed_url['host'], ':#?[]' ) )
|
||||||
return false;
|
return false;
|
||||||
|
|
||||||
$parsed_home = @parse_url( get_option( 'home' ) );
|
$parsed_home = @parse_url( get_option( 'home' ) );
|
||||||
@ -473,8 +474,7 @@ function wp_http_validate_url( $url ) {
|
|||||||
}
|
}
|
||||||
if ( $ip ) {
|
if ( $ip ) {
|
||||||
$parts = array_map( 'intval', explode( '.', $ip ) );
|
$parts = array_map( 'intval', explode( '.', $ip ) );
|
||||||
if ( '127.0.0.1' === $ip
|
if ( 127 === $parts[0] || 10 === $parts[0]
|
||||||
|| ( 10 === $parts[0] )
|
|
||||||
|| ( 172 === $parts[0] && 16 <= $parts[1] && 31 >= $parts[1] )
|
|| ( 172 === $parts[0] && 16 <= $parts[1] && 31 >= $parts[1] )
|
||||||
|| ( 192 === $parts[0] && 168 === $parts[1] )
|
|| ( 192 === $parts[0] && 168 === $parts[1] )
|
||||||
) {
|
) {
|
||||||
|
Loading…
Reference in New Issue
Block a user